Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.56% | — | Spirit FrameworkAI | 12/9/2025 | 17/6/2026 | The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in… | |
| Analizada | Media (6.5) | 0.60% | — | Opensecurity Mobile Security Framework | 2/9/2025 | 17/6/2026 | MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any directory writable by the user of the MobSF process. This issue has been patched in version 4.4.1. | |
| Analizada | Baja (1.3) | 0.78% | — | Opensecurity Mobile Security Framework | 2/9/2025 | 17/6/2026 | MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.commonprefix, which allows an authenticated user to download files outside the DWD_DIR download directory from "neighboring" directories whose absolute paths begin with the… | |
| Aplazada | Alta (8.5) | 0.33% | — | Scriptsbundle Exertio FrameworkAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scriptsbundle Exertio Framework exertio-framework allows Blind SQL Injection.This issue affects Exertio Framework: from n/a through <= 1.3.3. | |
| Aplazada | Alta (8.8) | 0.37% | — | Imran Tauqeer Cubewp-frameworkAICubewpAI | 20/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This issue affects CubeWP: from n/a through <= 1.1.24. | |
| Aplazada | Alta (7.1) | 0.24% | — | Vikas Sharma Iframe BlockAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Sharma iFrame Block allows Stored XSS. This issue affects iFrame Block: from n/a through 0.1.1. | |
| Aplazada | Media (6.5) | 0.31% | — | Logicdata Ecommerce FrameworkAI | 19/8/2025 | 17/6/2026 | An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5.0.9.7000 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Aplazada | Media (5.3) | 0.50% | — | Logicdata Ecommerce FrameworkAI | 19/8/2025 | 17/6/2026 | An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user accounts via a bruteforce attack. | |
| Aplazada | Media (5.9) | 2.1% | 💥 Exploit | Apache TomcatAIEclipse JettyAIVmware FrameworkAI | 18/8/2025 | 17/6/2026 | Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when all the following are true: We have verified that applications deployed on Apache Tomcat or Eclipse Jetty are not vulnerable, as long as… | |
| Aplazada | Media (5.4) | 0.24% | — | Tinywebgallery Advanced IframeAI | 16/8/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in version less than, or equal to, 2025.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Analizada | Media (5.5) | 0.19% | — | Adobe Framemaker | 12/8/2025 | 17/6/2026 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.22% | — | Adobe Framemaker | 12/8/2025 | 17/6/2026 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.22% | — | Adobe Framemaker | 12/8/2025 | 17/6/2026 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.22% | — | Adobe Framemaker | 12/8/2025 | 17/6/2026 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.22% | — | Adobe Framemaker | 12/8/2025 | 17/6/2026 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Media (6.5) | 0.49% | — | Openorange Business FrameworkAI | 7/8/2025 | 17/6/2026 | OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write to the installation path. In combination with the application's behavior of loading DLLs from this location, this allows for DLL hijacking and may result in arbitrary… | |
| Aplazada | Media (6.4) | 0.30% | — | Tinywebgallery Advanced IframeAI | 26/7/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.5) | 0.31% | — | SAP Fica ODN FrameworkAI | 23/7/2025 | 17/6/2026 | SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no impact on confidentiality of the… | |
| Analizada | Media (6.4) | 0.27% | — | Oracle Applications Framework | 15/7/2025 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the… | |
| Analizada | Media (4.3) | 0.20% | — | Dradisframework Dradis | 10/7/2025 | 17/6/2026 | In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs. | |
| Modificada | Media (6.5) | 0.33% | — | Jenkins Warrior Framework | 9/7/2025 | 17/6/2026 | Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Analizada | Alta (7.8) | 0.19% | — | Adobe Framemaker | 8/7/2025 | 17/6/2026 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.19% | — | Adobe Framemaker | 8/7/2025 | 17/6/2026 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.23% | — | Adobe Framemaker | 8/7/2025 | 17/6/2026 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.21% | — | Adobe Framemaker | 8/7/2025 | 17/6/2026 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |