Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.9%💥 PoCStimulsoft DesignerStimulsoft Viewer27/3/20239/7/2026
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an attacker may include source code which…
ModificadaCrítica (9.8)3.3%💥 ExploitTshirtecommerce Custom Product Designer22/3/202317/6/2026
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which…
ModificadaCrítica (9.8)3.3%💥 ExploitTshirtecommerce Custom Product Designer22/3/202317/6/2026
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is…
ModificadaMedia (5.4)0.63%—Solwininfotech Blog Designer30/1/202317/6/2026
The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModificadaMedia (5.4)0.44%—Infornweb News & Blog Designer Pack30/1/202317/6/2026
The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
AnalizadaMedia (5.4)0.47%—Infornweb Posts List Designer30/1/202317/6/2026
The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege…
ModificadaAlta (7.8)0.30%—Qlik Nprinting Designer26/1/202317/6/2026
Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.
ModificadaAlta (8.8)0.91%—Smackcoders Visual Email Designer FOR Woocommerce2/1/202317/6/2026
The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author.
ModificadaAlta (7.2)1.3%—Kadencewp Kadence Woocommerce Email Designer25/10/202217/6/2026
The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
ModificadaMedia (6.1)0.60%—Brinidesigner Awesome Filterable Portfolio23/9/202217/6/2026
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress.
ModificadaMedia (5.3)0.70%—Brinidesigner Awesome Filterable Portfolio23/9/202217/6/2026
Unauthenticated Plugin Settings Change vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress.
ModificadaAlta (7.8)0.31%—Fatek Fvdesigner31/8/202217/6/2026
FATEK FvDesigner version 1.5.103 and prior is vulnerable to an out-of-bounds write while processing project files. If a valid user is tricked into using maliciously crafted project files, an attacker could achieve arbitrary code execution.
ModificadaAlta (7.8)0.35%—Sick Safety Designer19/7/202217/6/2026
A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the current user…
ModificadaAlta (7.8)0.35%—Sick Flexi Soft Designer19/7/202217/6/2026
A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.9.4 SP1 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the…
ModificadaAlta (7.8)0.24%—SAP Powerdesigner Proxy14/6/202217/6/2026
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated privileges of the application during…
ModificadaAlta (7.8)0.20%—Siemens Xpedition Designer14/6/202217/6/2026
A vulnerability has been identified in Xpedition Designer VX.2.10 (All versions < VX.2.10 Update 13), Xpedition Designer VX.2.11 (All versions < VX.2.11 Update 11), Xpedition Designer VX.2.12 (All versions < VX.2.12 Update 5), Xpedition Designer VX.2.13 (All versions < VX.2.13 Update 1). The affected application…
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaCrítica (9.8)0.85%—Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data TransferMitsubishielectric EM Configurator+2519/5/202217/6/2026
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed,…
ModificadaAlta (8.8)0.60%—Radykal Fancy Product Designer19/4/202217/6/2026
The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versions up to, and including, 4.7.5.
ModificadaAlta (7.8)0.97%—Fatek Fvdesigner25/2/202217/6/2026
The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code
ModificadaAlta (7.8)2.0%—Fatek Fvdesigner25/2/202217/6/2026
The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
ModificadaAlta (7.8)2.0%—Fatek Fvdesigner25/2/202217/6/2026
The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (4.9)1.4%—Radykal Fancy Product Designer16/2/202217/6/2026
The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inject arbitrary SQL queries to obtain sensitive information, in…
ModificadaCrítica (9.8)1.3%—Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+4211/2/202217/6/2026
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.