Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 0.25% | — | 3DS 3dpassportAI3dswymerAI | 27/8/2026 | 8/9/2026 | An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts. | |
| Analizada | Media (6.1) | 0.20% | — | 3dswymer | 13/10/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (6.1) | 0.20% | — | 3dswymer | 13/10/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Alta (8.7) | 0.32% | — | 3DS 3dexperienceAI3dswymerAI | 17/3/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DPlay in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Alta (7.7) | 0.34% | — | 3dswymerAI | 16/10/2024 | 17/6/2026 | An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data. | |
| Aplazada | Alta (8.7) | 0.39% | — | 3dswymerAI | 19/9/2024 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Media (5.4) | 0.25% | — | 3DS 3ddashboardAI3dswymerAI | 17/5/2024 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code. | |
| Modificada | Media (5.4) | 0.39% | — | Dassault 3dswymer 3dexperience 2022Dassault 3dswymer 3dexperience 2023 | 21/11/2023 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023x allows an attacker to execute arbitrary script code. | |
| Modificada | Media (5.4) | 0.39% | — | Dassault 3dswymer 3dexperience 2022Dassault 3dswymer 3dexperience 2023 | 21/11/2023 | 17/6/2026 | Stored Cross-site Scripting (XSS) vulnerabilities affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023x allow an attacker to execute arbitrary script code. |