Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 1.1% | — | Toshiba PrinterAI | 14/6/2024 | 17/6/2026 | Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers by sending a HTTP request without authentication. An attacker can… | |
| Modificada | Alta (7.8) | 0.32% | — | Adobe Photoshop | 13/6/2024 | 17/6/2026 | Photoshop Desktop versions 24.7.3, 25.7 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation… | |
| Aplazada | Crítica (9.8) | 0.67% | — | Helloshop DeliveryorderautoupdateAI | 29/4/2024 | 17/6/2026 | SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function. | |
| Aplazada | Alta (7.1) | 0.35% | — | Marco Gasi Language Switcher FOR TransposhAI | 22/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Gasi Language Switcher for Transposh allows Reflected XSS.This issue affects Language Switcher for Transposh: from n/a through 1.5.9. | |
| Aplazada | Media (6.5) | 0.17% | — | Joshua Eldridge Easy CountdownerAI | 17/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Joshua Eldridge Easy CountDowner allows Stored XSS.This issue affects Easy CountDowner: from n/a through 1.0.8. | |
| Aplazada | Media (4.3) | 0.34% | — | Jaed Mosharraf AND Pluginbazar Team Open Close Woocommerce StoreAI | 17/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Jaed Mosharraf & Pluginbazar Team Open Close WooCommerce Store.This issue affects Open Close WooCommerce Store: from n/a through 4.9.1. | |
| Analizada | Media (5.5) | 0.34% | — | Adobe Photoshop | 10/4/2024 | 17/6/2026 | Photoshop Desktop versions 24.7.2, 25.3.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open… | |
| Modificada | Crítica (9.8) | 0.94% | — | Surajghosh Hospital Management System | 7/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Kashipara Hospital Management System up to 1.0. Affected by this issue is some unknown functionality of the file registration.php. The manipulation of the argument name/email/pass/gender/age/city leads to sql injection. The attack may be launched… | |
| Modificada | Crítica (9.8) | 0.69% | — | Surajghosh Hospital Management System | 7/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in Kashipara Hospital Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component Parameter Handler. The manipulation of the argument email/password leads to sql injection. The attack can be launched… | |
| Modificada | Crítica (9.8) | 0.88% | — | Imsurajghosh Student Information System | 8/12/2023 | 17/6/2026 | Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control. | |
| Modificada | Alta (8.8) | 1.5% | — | Imsurajghosh Student Information System | 7/12/2023 | 17/6/2026 | Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application. | |
| Modificada | Media (5.5) | 0.33% | — | Adobe Photoshop | 16/11/2023 | 17/6/2026 | Adobe Photoshop versions 24.7.1 (and earlier) and 25.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a… | |
| Modificada | Media (5.5) | 0.33% | — | Adobe Photoshop | 16/11/2023 | 17/6/2026 | Adobe Photoshop versions 24.7.1 (and earlier) and 25.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a… | |
| Modificada | Media (5.5) | 0.33% | — | Adobe Photoshop | 16/11/2023 | 17/6/2026 | Adobe Photoshop versions 24.7.1 (and earlier) and 25.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a… | |
| Modificada | Media (5.5) | 0.33% | — | Adobe Photoshop | 16/11/2023 | 17/6/2026 | Adobe Photoshop versions 24.7.1 (and earlier) and 25.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a… | |
| Modificada | Media (5.5) | 0.33% | — | Adobe Photoshop | 16/11/2023 | 17/6/2026 | Adobe Photoshop versions 24.7.1 (and earlier) and 25.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a… | |
| Modificada | Alta (7.8) | 0.32% | — | Adobe Photoshop | 16/11/2023 | 17/6/2026 | Adobe Photoshop versions 24.7.1 (and earlier) and 25.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (5.3) | 0.53% | — | Kaoshifeng Yunfan Learning Examination System | 4/11/2023 | 17/6/2026 | An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive information via the password parameter in the login function. | |
| Modificada | Crítica (9.8) | 0.80% | — | Toumorokoshi Transmute-core | 2/11/2023 | 17/6/2026 | Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code. | |
| Modificada | Alta (7.8) | 0.33% | — | Adobe Photoshop 2022Adobe Photoshop 2023Adobe Photoshop 2024 | 11/10/2023 | 17/6/2026 | Adobe Photoshop versions 23.5.5 (and earlier) and 24.7 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.34% | — | Adobe Photoshop | 7/9/2023 | 17/6/2026 | Adobe Photoshop versions 23.0.2 and 22.5.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious JPG file. | |
| Modificada | Media (5.5) | 0.49% | — | Adobe Photoshop | 7/9/2023 | 17/6/2026 | Adobe Photoshop version 22.5.1 and earlier versions are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Modificada | Alta (7.5) | 0.94% | — | Fujifilm Docuprint M265 Z FirmwareFujifilm Docuprint M268 Z FirmwareFujifilm Docuprint M225 Z FirmwareFujifilm Docuprint M225 DW Firmware+212 | 11/7/2023 | 17/6/2026 | Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information… | |
| Modificada | Alta (7.8) | 0.46% | — | Adobe Photoshop | 27/3/2023 | 17/6/2026 | Adobe Photoshop versions 23.5.3 (and earlier) and 24.1.1 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (5.5) | 0.33% | — | Adobe Photoshop | 17/2/2023 | 17/6/2026 | Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must… |