Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | 💥 PoC | Stimulsoft DesignerStimulsoft Viewer | 27/3/2023 | 9/7/2026 | Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an attacker may include source code which… | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Tshirtecommerce Custom Product Designer | 22/3/2023 | 17/6/2026 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which… | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Tshirtecommerce Custom Product Designer | 22/3/2023 | 17/6/2026 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is… | |
| Modificada | Media (5.4) | 0.63% | — | Solwininfotech Blog Designer | 30/1/2023 | 17/6/2026 | The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modificada | Media (5.4) | 0.44% | — | Infornweb News & Blog Designer Pack | 30/1/2023 | 17/6/2026 | The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Analizada | Media (5.4) | 0.47% | — | Infornweb Posts List Designer | 30/1/2023 | 17/6/2026 | The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege… | |
| Modificada | Alta (7.8) | 0.30% | — | Qlik Nprinting Designer | 26/1/2023 | 17/6/2026 | Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions. | |
| Modificada | Alta (8.8) | 0.91% | — | Smackcoders Visual Email Designer FOR Woocommerce | 2/1/2023 | 17/6/2026 | The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author. | |
| Modificada | Alta (7.2) | 1.3% | — | Kadencewp Kadence Woocommerce Email Designer | 25/10/2022 | 17/6/2026 | The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. | |
| Modificada | Media (6.1) | 0.60% | — | Brinidesigner Awesome Filterable Portfolio | 23/9/2022 | 17/6/2026 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress. | |
| Modificada | Media (5.3) | 0.70% | — | Brinidesigner Awesome Filterable Portfolio | 23/9/2022 | 17/6/2026 | Unauthenticated Plugin Settings Change vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress. | |
| Modificada | Alta (7.8) | 0.31% | — | Fatek Fvdesigner | 31/8/2022 | 17/6/2026 | FATEK FvDesigner version 1.5.103 and prior is vulnerable to an out-of-bounds write while processing project files. If a valid user is tricked into using maliciously crafted project files, an attacker could achieve arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.35% | — | Sick Safety Designer | 19/7/2022 | 17/6/2026 | A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the current user… | |
| Modificada | Alta (7.8) | 0.35% | — | Sick Flexi Soft Designer | 19/7/2022 | 17/6/2026 | A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.9.4 SP1 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the… | |
| Modificada | Alta (7.8) | 0.24% | — | SAP Powerdesigner Proxy | 14/6/2022 | 17/6/2026 | SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated privileges of the application during… | |
| Modificada | Alta (7.8) | 0.20% | — | Siemens Xpedition Designer | 14/6/2022 | 17/6/2026 | A vulnerability has been identified in Xpedition Designer VX.2.10 (All versions < VX.2.10 Update 13), Xpedition Designer VX.2.11 (All versions < VX.2.11 Update 11), Xpedition Designer VX.2.12 (All versions < VX.2.12 Update 5), Xpedition Designer VX.2.13 (All versions < VX.2.13 Update 1). The affected application… | |
| Modificada | Alta (8.1) | 2.0% | 💥 PoC | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Crítica (9.8) | 0.85% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data TransferMitsubishielectric EM Configurator+25 | 19/5/2022 | 17/6/2026 | Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed,… | |
| Modificada | Alta (8.8) | 0.60% | — | Radykal Fancy Product Designer | 19/4/2022 | 17/6/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versions up to, and including, 4.7.5. | |
| Modificada | Alta (7.8) | 0.97% | — | Fatek Fvdesigner | 25/2/2022 | 17/6/2026 | The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code | |
| Modificada | Alta (7.8) | 2.0% | — | Fatek Fvdesigner | 25/2/2022 | 17/6/2026 | The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution. | |
| Modificada | Alta (7.8) | 2.0% | — | Fatek Fvdesigner | 25/2/2022 | 17/6/2026 | The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution. | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (4.9) | 1.4% | — | Radykal Fancy Product Designer | 16/2/2022 | 17/6/2026 | The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inject arbitrary SQL queries to obtain sensitive information, in… | |
| Modificada | Crítica (9.8) | 1.3% | — | Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+42 | 11/2/2022 | 17/6/2026 | Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition. |