Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

1099 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.31%—Logicdata Ecommerce FrameworkAI19/8/202517/6/2026
An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5.0.9.7000 allows attackers to execute arbitrary code via uploading a crafted file.
AplazadaMedia (5.3)0.50%—Logicdata Ecommerce FrameworkAI19/8/202517/6/2026
An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user accounts via a bruteforce attack.
AplazadaMedia (5.9)2.1%💥 ExploitApache TomcatAIEclipse JettyAIVmware FrameworkAI18/8/202517/6/2026
Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when all the following are true: We have verified that applications deployed on Apache Tomcat or Eclipse Jetty are not vulnerable, as long as…
AplazadaMedia (6.5)0.49%—Openorange Business FrameworkAI7/8/202517/6/2026
OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write to the installation path. In combination with the application's behavior of loading DLLs from this location, this allows for DLL hijacking and may result in arbitrary…
AplazadaMedia (5.5)0.31%—SAP Fica ODN FrameworkAI23/7/202517/6/2026
SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no impact on confidentiality of the…
AnalizadaMedia (6.4)0.27%—Oracle Applications Framework15/7/202517/6/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the…
AnalizadaMedia (4.3)0.20%—Dradisframework Dradis10/7/202517/6/2026
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
ModificadaMedia (6.5)0.33%—Jenkins Warrior Framework9/7/202517/6/2026
Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
AnalizadaMedia (4.3)0.28%—Dradisframework Dradis5/7/202517/6/2026
Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network.
AplazadaMedia (6.5)0.45%—Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+133/7/202517/6/2026
ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization…
AplazadaMedia (6.5)0.60%—Vmware Spring FrameworkAI12/6/202517/6/2026
Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input. Specifically, an…
AplazadaAlta (7.1)0.18%—Uxper Civi FrameworkAI10/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework civi-framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through <= 2.1.6.
AplazadaMedia (5.3)0.19%—SAP Business ONE Integration FrameworkAI10/6/202517/6/2026
The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and availability.
AnalizadaMedia (5.1)0.32%—Yiiframework Yii2-redis5/6/202517/6/2026
The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands sequence to logs. Prior to version 2.0.20, AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to…
AplazadaBaja (3.1)0.42%—Vmware Spring FrameworkAI16/5/202517/6/2026
CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks. Affected Spring Products and Versions Mitigation Users of affected versions…
AnalizadaMedia (4.8)0.31%—Data443 Gdpr Framework15/5/202517/6/2026
The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaMedia (6.5)0.50%—Opensecurity Mobile Security Framework5/5/202517/6/2026
MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web interface is often granted to internal security teams, audit teams, and external vendors. MobSF…
AnalizadaAlta (8.6)0.32%—Opensecurity Mobile Security Framework5/5/202517/6/2026
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions up to and including 4.3.2. The vulnerability arises from improper sanitization of user-supplied SVG files…
AnalizadaMedia (6.5)0.69%—Haulmont Cuba PlatformHaulmont Cuba Rest APIHaulmont Jmix FrameworkHaulmont JPA WEB API22/4/202517/6/2026
Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing…
AnalizadaMedia (5.4)0.36%—Haulmont Cuba PlatformHaulmont Cuba Rest APIHaulmont Jmix FrameworkHaulmont JPA WEB API22/4/202517/6/2026
Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the input parameter, which consists of a file path and name, can be manipulated to return the Content-Type header with text/html if the name part ends with .html. This could…
AnalizadaMedia (6.5)0.72%—Haulmont Jmix Framework22/4/202517/6/2026
Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, attackers could manipulate the FileRef parameter to access files on the system where the Jmix application is deployed, provided the application server has the necessary…
AnalizadaMedia (5.4)0.33%—Oracle Applications Framework15/4/202517/6/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.…
AnalizadaMedia (5.4)0.36%—Oracle Applications Framework15/4/202517/6/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.…
AplazadaMedia (5.3)0.41%—Adianti FrameworkAI14/4/202517/6/2026
A vulnerability has been found in Adianti Framework up to 8.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 8.1 is…
AnalizadaMedia (6.1)0.24%—Yiiframework YII10/4/202517/6/2026
Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. Upgrade yiisoft/yii to version 1.1.31 or higher.