Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.29% | — | Silverstripe Framework | 10/4/2025 | 17/6/2026 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The payload would be sanitized… | |
| Analizada | Crítica (9.8) | 88% | ⚠ Explotación activa💥 Exploit | Yiiframework YII | 10/4/2025 | 17/6/2026 | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. | |
| Analizada | Crítica (9.8) | 0.54% | — | Totvs Framework (linha Protheus) | 9/4/2025 | 17/6/2026 | An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message. | |
| Analizada | Crítica (9.8) | 0.47% | — | Opensecurity Mobile Security Framework | 31/3/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to SSRF abuse using DNS rebinding technique. This vulnerability is… | |
| Aplazada | Alta (7.3) | 0.15% | — | Xiaomi Phone FrameworkAI | 27/3/2025 | 17/6/2026 | A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by attackers to Access sensitive methods. | |
| Aplazada | Media (5.5) | 0.15% | — | Xiaomi Phone FrameworkAI | 27/3/2025 | 17/6/2026 | A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by attackers to Access sensitive methods. | |
| Aplazada | Media (4.3) | 0.16% | — | Xiaomi Quick APP FrameworkAI | 27/3/2025 | 17/6/2026 | An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is caused by improper input validation and can be exploited by attackers tointent redriction. | |
| Analizada | Media (5.3) | 0.66% | — | Yiiframework YII | 24/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.62% | — | Yiiframework YII | 24/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to… | |
| Aplazada | Alta (7.2) | 31% | 💥 PoC | Horde IMPAIHorde Application FrameworkAI | 21/3/2025 | 17/6/2026 | Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025. | |
| Analizada | Crítica (9.1) | 80% | — | Yiiframework YII | 20/3/2025 | 17/6/2026 | In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a valid Behavior class name or configuration. This allows an attacker to instantiate arbitrary classes, passing parameters to their constructors and invoking… | |
| Aplazada | Media (6.9) | 0.48% | — | Viames Pair FrameworkAI | 17/3/2025 | 17/6/2026 | A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical. Affected by this vulnerability is the function getCookieContent of the file /src/UserRemember.php of the component PHP Object Handler. The manipulation of the argument cookieName leads to deserialization. The attack can be… | |
| Aplazada | Alta (8.6) | 0.33% | — | Freshface Fresh FrameworkAI | 15/3/2025 | 17/6/2026 | Missing Authorization vulnerability in FRESHFACE Fresh Framework fresh-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Fresh Framework: from n/a through <= 1.70.0. | |
| Aplazada | Crítica (10) | 0.50% | — | Freshface Fresh FrameworkAI | 10/3/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Fresh Framework fresh-framework allows Code Injection.This issue affects Fresh Framework: from n/a through <= 1.70.0. | |
| Analizada | Media (6.1) | 0.53% | — | Laravel Framework | 10/3/2025 | 17/6/2026 | The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page. | |
| Analizada | Media (6.1) | 0.60% | — | Laravel Framework | 10/3/2025 | 17/6/2026 | The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page. | |
| Aplazada | Alta (7.5) | 0.38% | — | CS FrameworkAI | 7/3/2025 | 17/6/2026 | The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via the get_widget_settings_json() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can… | |
| Aplazada | Alta (8.8) | 0.90% | — | CS FrameworkAI | 7/3/2025 | 17/6/2026 | The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cs_widget_file_delete() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary… | |
| Analizada | Media (6.9) | 0.75% | 💥 PoC | Laravel Framework | 5/3/2025 | 17/6/2026 | Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1. | |
| Analizada | Media (5.3) | 0.53% | — | Zframeworks ZZ | 3/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in zj1983 zz up to 2024-8. Affected by this vulnerability is an unknown functionality of the file /import_data_todb. The manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.53% | — | Zframeworks ZZ | 3/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in zj1983 zz up to 2024-8. Affected is an unknown function of the file /import_data_check. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.3) | 0.53% | — | Zframeworks ZZ | 3/3/2025 | 17/6/2026 | A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this… | |
| Analizada | Media (5.3) | 0.63% | — | Zframeworks ZZ | 3/3/2025 | 17/6/2026 | A vulnerability was found in zj1983 zz up to 2024-8. It has been declared as problematic. This vulnerability affects the function deleteLocalFile of the file src/main/java/com/futvan/z/system/zfile/ZfileAction.java of the component File Handler. The manipulation of the argument zids leads to denial of service. The… | |
| Analizada | Media (5.3) | 0.55% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in zj1983 zz up to 2024-8. This affects an unknown part of the file /resolve. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (5.3) | 0.53% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. Affected by this issue is the function sendNotice of the file src/main/java/com/futvan/z/erp/customer_notice/Customer_noticeAction.java of the component HTTP Request Handler. The manipulation of the argument url leads to… |