Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

192 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)3.6%—Adobe After Effects25/6/202017/6/2026
Adobe After Effects versions 17.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution .
ModificadaAlta (7.8)3.3%—Adobe After Effects25/6/202017/6/2026
Adobe After Effects versions 17.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
ModificadaAlta (7.8)8.7%—Adobe After Effects25/6/202017/6/2026
Adobe After Effects versions 17.1 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
ModificadaAlta (7.8)8.4%—Adobe After Effects25/6/202017/6/2026
Adobe After Effects versions 17.1 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
ModificadaCrítica (9.8)4.2%—Effect Project Effect2/4/202017/6/2026
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
ModificadaCrítica (9.8)5.6%—Adobe After Effects20/2/202017/6/2026
Adobe After Effects versions 16.1.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (7.8)3.2%—Adobe After Effects14/8/201917/6/2026
Adobe After Effects versions 16 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaMedia (4.3)2.0%—Banner Effect Header Project Banner Effect Header3/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Banner Effect Header plugin before 1.2.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the banner_effect_divid parameter in the BannerEffectOptions page to wp-admin/options-general.php.
ModificadaMedia (6.8)1.2%—Banner Effect Header Project Banner Effect Header8/1/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Banner Effect Header plugin 1.2.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the banner_effect_email parameter in the BannerEffectOptions page to…
ModificadaMedia (5)2.4%—Blinkwebeffects Social-media-widget25/4/201316/6/2026
Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Trojan Horse), which allows remote attackers to force the upload of arbitrary files.
ModificadaMedia (4.3)3.7%💥 ExploitZooeffect20/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in the ZooEffect plugin 1.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: some of these details are obtained from third party information. NOTE: this has been disputed by a third party.
ModificadaMedia (6.9)0.36%—Sowsoft Effective File Search6/9/201216/6/2026
Untrusted search path vulnerability in Effective File Search 6.7 allows local users to gain privileges via a Trojan horse ztvunrar36.dll file in the current working directory, as demonstrated by a directory that contains a .efs file. NOTE: the provenance of this information is unknown; the details are obtained solely…
ModificadaAlta (7.5)0.99%💥 ExploitSumeffect Digishop30/12/201016/6/2026
SQL injection vulnerability in cart.php in digiSHOP 2.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vulnerability than CVE-2005-4614.1.
ModificadaAlta (9.3)5.8%💥 ExploitEffectmatrix Magic Morph24/9/200916/6/2026
Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor file.
ModificadaAlta (9.3)13%💥 ExploitEffectmatrix Total Video Player23/1/200916/6/2026
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\DefaultSkin.ini file with a large ColumnHeaderSpan value.
ModificadaMedia (6.8)2.1%💥 ExploitSUM Effect Software Digishop5/10/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in cart.php in Sum Effect Software digiSHOP 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sortBy or (2) search parameters.
ModificadaAlta (7.5)1.5%—SUM Effect Software Digishop31/12/200516/6/2026
Multiple SQL injection vulnerabilities in digiSHOP 3.1.17 and earlier allow remote attackers to execute arbitrary SQL commands or obtain the full installation path via (1) the c parameter in cart.php and (2) unspecified search module parameters.
Orbitaley — Vulnerabilidades