Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (10) | 0.81% | — | 3DS 3dexperienceAI3DS Station Launcher APPAI | 28/7/2026 | 30/7/2026 | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution. | |
| Analizada | Crítica (9.1) | 0.27% | — | 3DS 3dexperience | 31/3/2026 | 17/6/2026 | A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to read or write files in specific directories on the server. | |
| Analizada | Media (5.4) | 0.17% | — | 3DS 3dexperience | 31/3/2026 | 17/6/2026 | A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (5.4) | 0.17% | — | 3DS 3dexperience | 31/3/2026 | 17/6/2026 | A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (5.4) | 0.19% | — | 3DS 3dexperience Enovia | 8/12/2025 | 17/6/2026 | A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (5.4) | 0.19% | — | 3DS 3dexperience Enovia | 24/11/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (5.4) | 0.20% | — | 3DS 3dexperience Enovia | 13/10/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (5.4) | 0.20% | — | 3DS 3dexperience Enovia | 13/10/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Crítica (9) | 0.90% | — | 3DS 3dexperience Station Launcher APPAI | 13/10/2025 | 25/9/2026 | An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine. | |
| Aplazada | Alta (8.7) | 0.41% | — | 3DS 3dexperience Project Portfolio ManagerAI | 16/6/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Opportunity Management in Project Portfolio Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Alta (8.7) | 0.32% | — | 3DS 3dexperienceAI3DS Service Process EngineerAI | 30/5/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Alta (8.7) | 0.32% | — | 3DS 3dexperienceAI | 30/5/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Alta (8.7) | 0.32% | — | 3DS 3dexperienceAI | 30/5/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Alta (8.7) | 0.32% | — | 3DS 3dexperienceAI3DS Product ManagerAI | 30/5/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Alta (8.7) | 0.32% | — | 3DS 3dexperienceAI | 30/5/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Results Analytics in Multidisciplinary Optimization Engineer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Alta (8.7) | 0.32% | — | 3DS 3dexperience Product ManagerAI | 30/5/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Model Definition in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Alta (8.7) | 0.32% | — | 3DS 3dexperienceAI3DS Project Portfolio ManagerAI | 30/5/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Alta (8.7) | 0.32% | — | 3DS 3dexperienceAI | 30/5/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Compare in Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (5.4) | 0.25% | — | 3DS 3dexperience Enovia | 17/3/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Route Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (5.4) | 0.25% | — | 3DS 3dexperience Enovia | 17/3/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Project Gantt in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (5.4) | 0.25% | — | 3DS 3dexperience Enovia | 17/3/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Meeting Management in ENOVIA Change Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (5.4) | 0.25% | — | 3DS 3dexperience Enovia | 17/3/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (5.4) | 0.25% | — | 3DS 3dexperience Enovia | 17/3/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Engineering Release in ENOVIA Product Engineering Specialist from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Alta (8.7) | 0.32% | — | 3DS 3dexperienceAI3dswymerAI | 17/3/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DPlay in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (5.4) | 0.25% | — | 3DS 3dexperience Enovia | 17/3/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3D Navigate in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session. |