Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.53% | — | Designervily GreenifyAI | 6/11/2025 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Greenify greenify allows PHP Local File Inclusion.This issue affects Greenify: from n/a through <= 2.2. | |
| Aplazada | Alta (7.1) | 0.23% | — | Pencidesign Penci Bookmark & FollowAI | 6/11/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Bookmark & Follow penci-bookmark-follow allows Reflected XSS.This issue affects Penci Bookmark & Follow: from n/a through < 2.4. | |
| Analizada | Crítica (9.8) | 1.2% | — | Magdesign Pocketvj Control Panel Firmware | 5/11/2025 | 17/6/2026 | PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in the opacityValue POST parameter before passing it to a shell command, allowing remote attackers to execute arbitrary commands… | |
| Aplazada | Alta (7.6) | 0.32% | — | Silabs Z-wave PIR Sensor Reference DesignAISilabs SisdkAI | 31/10/2025 | 17/6/2026 | When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-secure device. This vulnerability exists in Silicon Labs' Z-Wave PIR Sensor Reference design delivered as part of SiSDK v2025.6.0 and v2025.6.1. | |
| Aplazada | Alta (8.6) | 1.9% | 💥 Exploit | Woocommerce Designer PROAI | 31/10/2025 | 17/6/2026 | The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read. | |
| Analizada | Media (6.1) | 0.20% | — | Salsa.digital Civictheme Design System | 30/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CivicTheme Design System allows Cross-Site Scripting (XSS).This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0. | |
| Analizada | Alta (7.5) | 0.31% | — | Salsa.digital Civictheme Design System | 30/10/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0. | |
| Aplazada | Media (5.3) | 0.27% | — | Solwin Blog Designer PROAI | 29/10/2025 | 5/10/2026 | Missing Authorization vulnerability in solwin Blog Designer PRO blog-designer-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blog Designer PRO: from n/a through <= 3.4.8. | |
| Aplazada | Media (6.5) | 0.17% | — | Designinvento DirectorypressAI | 27/10/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento DirectoryPress directorypress allows DOM-Based XSS.This issue affects DirectoryPress: from n/a through <= 3.6.25. | |
| Aplazada | Crítica (9.8) | 33% | 💥 PoC | Woocommerce Designer PROAI | 24/10/2025 | 17/6/2026 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.53% | — | Designthemes Single PropertyAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection.This issue affects Single Property: from n/a through <= 2.8. | |
| Aplazada | Alta (8.8) | 0.53% | — | Designthemes Knowledge BaseAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9. | |
| Aplazada | Alta (8.8) | 0.53% | — | Designthemes KriyaAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects Kriya: from n/a through <= 3.4. | |
| Aplazada | Alta (8.1) | 0.52% | — | Designervily XcareAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Xcare xcare allows PHP Local File Inclusion.This issue affects Xcare: from n/a through < 6.5. | |
| Aplazada | Alta (8.1) | 0.52% | — | Designervily KarzoAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Karzo karzo allows PHP Local File Inclusion.This issue affects Karzo: from n/a through < 2.6. | |
| Aplazada | Alta (7.1) | 0.25% | — | Designthemes TrissAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Triss triss allows Reflected XSS.This issue affects Triss: from n/a through <= 2.6. | |
| Aplazada | Media (6.3) | 0.24% | — | Andondesign U-design-coreAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in AndonDesign UDesign Core u-design-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UDesign Core: from n/a through <= 4.14.0. | |
| Aplazada | Alta (8.8) | 0.61% | — | Designthemes Solar EnergyAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue affects Solar Energy: from n/a through <= 3.5. | |
| Aplazada | Alta (7.1) | 0.25% | — | Andondesign U-design-coreAI | 22/10/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesign Core u-design-core allows Reflected XSS.This issue affects UDesign Core: from n/a through <= 4.14.0. | |
| Aplazada | Media (6.4) | 0.19% | — | Material Design Iconic Font IntegrationAI | 22/10/2025 | 17/6/2026 | The Material Design Iconic Font Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdiconic' shortcode in all versions up to, and including, 2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.7) | 0.37% | — | Rockwellautomation Studio 5000 Logix DesignerAIRockwellautomation Armorstart ClassicAI | 14/10/2025 | 17/6/2026 | A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the ArmorStart Classic distributed motor controller, resulting in denial-of-service. This vulnerability is possible due to the input of invalid values into Component Object Model (COM) methods. | |
| Aplazada | Crítica (9.8) | 0.81% | — | Woocommerce Designer PROAI | 11/10/2025 | 17/6/2026 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it… | |
| Aplazada | Media (4.3) | 0.21% | — | WdesignkitAI | 4/10/2025 | 17/6/2026 | The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress is vulnerable to missing authorization via the wdkit_handle_review_submission function in versions less than, or equal to, 1.2.16. This is due to the plugin not properly verifying that a user is… | |
| Aplazada | Media (5.5) | 0.22% | — | Ultimate Multi Design Video CarouselAI | 3/10/2025 | 17/6/2026 | The Ultimate Multi Design Video Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts… | |
| Analizada | Alta (8.5) | 0.18% | — | NI Circuit Design Suite | 30/9/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds read in DefaultFontOptions() when using SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted… |