Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.6) | 0.11% | — | Vmware Spring Framework | 20/3/2026 | 17/6/2026 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46. | |
| Analizada | Crítica (10) | 0.48% | 💥 PoC | Templaza Astroid Framework | 5/3/2026 | 17/6/2026 | A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution. | |
| Aplazada | Alta (7.5) | 0.29% | — | Modeltheme FrameworkAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in modeltheme ModelTheme Framework modeltheme-framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ModelTheme Framework: from n/a through < 2.0.0. | |
| Aplazada | Crítica (9.5) | 1.6% | 💥 PoC | JoomlaAITassos FrameworkAI | 20/2/2026 | 17/6/2026 | The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction. | |
| Aplazada | Media (6.4) | 0.31% | — | Apollo13 Framework ExtensionsAI | 19/2/2026 | 17/6/2026 | The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_link’ parameter in all versions up to, and including, 1.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Analizada | Alta (8.2) | 0.10% | — | Dell Update Package Framework | 12/2/2026 | 17/6/2026 | Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Crítica (9.9) | 0.52% | — | SAP Netweaver Application Server AbapSAP S/4hanaSAP Webclient UI Framework | 10/2/2026 | 17/6/2026 | An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on… | |
| Aplazada | Alta (8.5) | 0.15% | — | Wondershare Application Framework ServiceAI | 6/2/2026 | 17/6/2026 | Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific directory locations to hijack the… | |
| Aplazada | Crítica (9.3) | 0.58% | — | Lexmark Embedded Solutions FrameworkAI | 3/2/2026 | 17/6/2026 | An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code. | |
| Aplazada | Alta (8.8) | 0.69% | — | Lexmark Embedded Solutions FrameworkAI | 3/2/2026 | 17/6/2026 | A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user. | |
| Aplazada | Alta (7.5) | 0.36% | — | Talemy Spirit FrameworkAI | 2/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Talemy Spirit Framework allows PHP Local File Inclusion.This issue affects Spirit Framework: from n/a through 1.2.13. | |
| Aplazada | Alta (8.5) | 0.17% | — | Iskysoft Application Framework ServiceAI | 1/2/2026 | 17/6/2026 | Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that would be run with the… | |
| Analizada | Media (6.8) | 0.10% | — | Icinga Powershell Framework | 29/1/2026 | 17/6/2026 | The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in the exposure of… | |
| Aplazada | Media (6.9) | 0.15% | — | Praydog ReframeworkAI | 27/1/2026 | 17/6/2026 | An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 leads to a heap-buffer overflow when a recursive error occurs. | |
| Analizada | Media (4.7) | 0.24% | — | Theupdateframework Go-tuf | 27/1/2026 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. Starting in version 2.0.0 and prior to version 2.4.1, if an application accepts a map file… | |
| Analizada | Media (4.8) | 0.35% | — | Opensecurity Mobile Security Framework | 27/1/2026 | 17/6/2026 | MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vulnerability in MobSF's Android manifest analysis allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session by uploading a malicious APK. The `android:host`… | |
| Aplazada | Media (4.3) | 0.35% | — | Sizam Rehub FrameworkAI | 22/1/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in sizam REHub Framework rehub-framework allows Retrieve Embedded Sensitive Data.This issue affects REHub Framework: from n/a through < 19.9.9.4. | |
| Analizada | Alta (7.5) | 0.22% | — | Theupdateframework Go-tuf | 22/1/2026 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification… | |
| Analizada | Alta (7.5) | 0.59% | — | Theupdateframework Go-tuf | 22/1/2026 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic… | |
| Analizada | Media (5.4) | 0.21% | — | Oracle Utilities Framework | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General). Supported versions that are affected are 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4 and 25.10. Easily exploitable vulnerability allows low privileged attacker with network access… | |
| Aplazada | Media (5.3) | 0.26% | — | Pegasystems Customer Service FrameworkAI | 13/1/2026 | 17/6/2026 | Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file. | |
| Aplazada | Alta (7.5) | 0.45% | — | G5theme Handmade-frameworkAI | 8/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in G5Theme Handmade Framework handmade-framework allows PHP Local File Inclusion.This issue affects Handmade Framework: from n/a through <= 3.9. | |
| Aplazada | Alta (7.5) | 0.34% | — | Sizam Rehub FrameworkAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in sizam REHub Framework rehub-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects REHub Framework: from n/a through <= 19.9.5. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Ricetheme Felan FrameworkAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allows SQL Injection.This issue affects Felan Framework: from n/a through <= 1.1.3. | |
| Aplazada | Crítica (9.8) | 0.49% | — | Ricetheme Felan FrameworkAI | 8/1/2026 | 7/10/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allows Authentication Abuse.This issue affects Felan Framework: from n/a through <= 1.1.3. |