Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.28% | — | Imran Tauqeer Cubewp Cubewp FrameworkAI | 29/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CubeWP: from n/a through <= 1.1.27. | |
| Aplazada | Media (5.9) | 0.21% | — | Basticom FrameworkAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basticom Basticom Framework basticom-framework allows Stored XSS.This issue affects Basticom Framework: from n/a through <= 1.5.2. | |
| Aplazada | Media (5.3) | 0.29% | — | Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho Analytics Community Dashboard FrameworkAI | 15/12/2025 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet. | |
| Aplazada | Media (6.4) | 0.30% | — | Redux FrameworkAI | 13/12/2025 | 17/6/2026 | The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 4.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (6.5) | 0.23% | — | Sizam Rehub FrameworkAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam REHub Framework rehub-framework allows Stored XSS.This issue affects REHub Framework: from n/a through < 19.9.9.7. | |
| Aplazada | Media (6.6) | 0.34% | — | SAP Internet Communication FrameworkAI | 9/12/2025 | 17/6/2026 | The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identification allowing an attacker to reuse authorization tokens, violating secure authentication practices causing low impact on Confidentiality, Integrity and Availability of the application. | |
| Aplazada | Crítica (9.8) | 76% | 💥 Exploit | Sneeit FrameworkAI | 25/11/2025 | 17/6/2026 | The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pagination_callback() function. This is due to the function accepting user input and then passing that through call_user_func(). This makes it possible for unauthenticated… | |
| Aplazada | Media (6.9) | 0.56% | — | Egovframework Egovframe-common-componentsAI | 19/11/2025 | 14/7/2026 | eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vulnerability via the /utl/wed/insertImage.do and /utl/wed/insertImageCk.do image upload endpoints. These controllers accept multipart requests without authentication, pass the uploaded content to a… | |
| Aplazada | Media (5.3) | 0.34% | — | WP Headless CMS FrameworkAI | 13/11/2025 | 17/6/2026 | The WP Headless CMS Framework plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.15. This is due to the plugin only checking for the existence of the Authorization header in a request when determining if the nonce protection should be bypassed. This makes it… | |
| Aplazada | Media (6.4) | 0.19% | — | Open Source Genesis Genesis FrameworkAI | 25/10/2025 | 17/6/2026 | The Open Source Genesis Framework theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.3) | 0.24% | — | Oracle Applications Framework | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Media (4.3) | 0.24% | — | Oracle Applications Framework | 21/10/2025 | 30/9/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Aplazada | Media (4.3) | 0.31% | — | Vmware Spring FrameworkAI | 16/10/2025 | 17/6/2026 | STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: MitigationUsers of affected versions should upgrade to the corresponding fixed version. Affected version(s)Fix… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Felan FrameworkAI | 16/10/2025 | 17/6/2026 | The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password in the 'fb_ajax_login_or_register' function and in the 'google_ajax_login_or_register' function. This makes it possible for unauthenticated attackers to log… | |
| Aplazada | Media (5.3) | 0.32% | — | Felan FrameworkAI | 16/10/2025 | 17/6/2026 | The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_plugin_actions' function called via an AJAX action in versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to activate or deactivate… | |
| Analizada | Media (5.7) | 0.72% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 14/10/2025 | 17/6/2026 | Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Spirit FrameworkAI | 3/10/2025 | 17/6/2026 | The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.2.14. This is due to the custom_actions() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible for unauthenticated attackers to log in… | |
| Aplazada | Alta (7) | 0.19% | — | QOS Logback-coreAIJaninoAIVmware Spring FrameworkAI | 1/10/2025 | 25/6/2026 | ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution. A… | |
| Aplazada | Crítica (9.8) | 0.37% | — | Thrivex Blogging FrameworkAI | 29/9/2025 | 17/6/2026 | An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint. | |
| Aplazada | Alta (7.5) | 0.46% | — | Vmware FrameworkAIVmware SecurityAI | 16/9/2025 | 17/6/2026 | The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using… | |
| Aplazada | Alta (7.5) | 0.56% | — | Spirit FrameworkAI | 12/9/2025 | 17/6/2026 | The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in… | |
| Analizada | Media (6.5) | 0.60% | — | Opensecurity Mobile Security Framework | 2/9/2025 | 17/6/2026 | MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any directory writable by the user of the MobSF process. This issue has been patched in version 4.4.1. | |
| Analizada | Baja (1.3) | 0.78% | — | Opensecurity Mobile Security Framework | 2/9/2025 | 17/6/2026 | MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.commonprefix, which allows an authenticated user to download files outside the DWD_DIR download directory from "neighboring" directories whose absolute paths begin with the… | |
| Aplazada | Alta (8.5) | 0.33% | — | Scriptsbundle Exertio FrameworkAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scriptsbundle Exertio Framework exertio-framework allows Blind SQL Injection.This issue affects Exertio Framework: from n/a through <= 1.3.3. | |
| Aplazada | Alta (8.8) | 0.37% | — | Imran Tauqeer Cubewp-frameworkAICubewpAI | 20/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This issue affects CubeWP: from n/a through <= 1.1.24. |