Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1339 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.34%—Adobe Framemaker14/4/202628/8/2026
Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.38%—Adobe Framemaker14/4/202628/8/2026
Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (8.6)0.29%—Adobe Framemaker14/4/202628/8/2026
Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that search…
ModificadaAlta (7.5)2.4%—Microsoft .netMicrosoft .net Framework14/4/202625/7/2026
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (5.9)0.66%—Microsoft .net Framework14/4/202625/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
ModificadaAlta (7.5)1.3%—Microsoft .net Framework14/4/202615/7/2026
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
AplazadaAlta (7.1)0.19%—Adianti FrameworkAI12/4/202617/6/2026
Adianti Framework 5.5.0 and 5.6.0 contains an SQL injection vulnerability that allows authenticated users to manipulate database queries by injecting SQL code through the name field in SystemProfileForm. Attackers can submit crafted SQL statements in the profile edit endpoint to modify user credentials and gain…
AnalizadaAlta (8.5)0.30%—Circl AIL Framework8/4/202624/7/2026
AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality. When item content longer than 800 characters was processed, attacker-controlled content was returned…
AplazadaMedia (5.5)0.69%—Heriklyma CppwebframeworkAI6/4/202617/6/2026
A vulnerability was detected in HerikLyma CPPWebFramework up to 3.1. This issue affects some unknown processing. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue…
AnalizadaAlta (8.2)0.52%—Ash-hq ASH Framework2/4/202624/7/2026
Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 unconditionally creates a new Erlang atom via Module.concat([value]) for any user-supplied binary string that starts with "Elixir.", before verifying whether the referenced…
AnalizadaAlta (8.8)0.31%—Nvidia Bionemo Framework31/3/202624/7/2026
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
AnalizadaCrítica (9.8)0.47%—Nvidia Bionemo Framework31/3/202624/7/2026
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
AnalizadaMedia (6.5)0.40%—Opensecurity Mobile Security Framework26/3/202617/6/2026
MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `mobsf/MobSF/utils.py` (lines 542-566) uses Python string formatting (`%`) to construct SQL queries with table names read from a SQLite database's `sqlite_master` table. When a security analyst uses…
AplazadaAlta (7.1)0.25%—G5theme Darna FrameworkAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Darna Framework darna-framework allows Reflected XSS.This issue affects Darna Framework: from n/a through <= 2.9.
AplazadaAlta (7.1)0.25%—G5theme Wolverine FrameworkAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Wolverine Framework wolverine-framework allows Reflected XSS.This issue affects Wolverine Framework: from n/a through <= 1.9.
AplazadaAlta (7.1)0.23%—G5theme Handmade FrameworkAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Handmade Framework handmade-framework allows Reflected XSS.This issue affects Handmade Framework: from n/a through <= 3.9.
AnalizadaMedia (5.9)0.39%—Vmware Spring Framework20/3/202617/6/2026
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16,…
AnalizadaBaja (2.6)0.11%—Vmware Spring Framework20/3/202617/6/2026
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
AnalizadaCrítica (10)0.48%💥 PoCTemplaza Astroid Framework5/3/202617/6/2026
A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.
AplazadaAlta (7.5)0.29%—Modeltheme FrameworkAI20/2/202617/6/2026
Missing Authorization vulnerability in modeltheme ModelTheme Framework modeltheme-framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ModelTheme Framework: from n/a through < 2.0.0.
AplazadaCrítica (9.5)1.6%💥 PoCJoomlaAITassos FrameworkAI20/2/202617/6/2026
The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.
AplazadaMedia (6.5)0.23%—Tinywebgallery Advanced IframeAI19/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdempfle Advanced iFrame advanced-iframe allows DOM-Based XSS.This issue affects Advanced iFrame: from n/a through <= 2025.10.
AplazadaMedia (6.4)0.31%—Apollo13 Framework ExtensionsAI19/2/202617/6/2026
The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_link’ parameter in all versions up to, and including, 1.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access…
AnalizadaAlta (8.2)0.10%—Dell Update Package Framework12/2/202617/6/2026
Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaCrítica (9.9)0.52%—SAP Netweaver Application Server AbapSAP S/4hanaSAP Webclient UI Framework10/2/202617/6/2026
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on…
Orbitaley — Vulnerabilidades