Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.54% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in zj1983 zz up to 2024-8. Affected by this vulnerability is the function getUserList of the file src/main/java/com/futvan/z/system/zrole/ZroleAction.java. The manipulation of the argument roleid leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (5.3) | 0.57% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in zj1983 zz up to 2024-8. Affected is the function GetDBUser of the file src/main/java/com/futvan/z/system/zorg/ZorgAction.java. The manipulation of the argument user_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (4.8) | 0.40% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as problematic. This issue affects some unknown processing of the component Customer Information Handler. The manipulation of the argument Customer Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability was found in zj1983 zz up to 2024-8 and classified as critical. Affected by this issue is the function getUserOrgForUserId of the file src/main/java/com/futvan/z/system/zorg/ZorgAction.java. The manipulation of the argument userID leads to sql injection. The attack may be launched remotely. The exploit… | |
| Analizada | Media (5.3) | 0.54% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability has been found in zj1983 zz up to 2024-8 and classified as critical. Affected by this vulnerability is the function getOaWid of the file src/main/java/com/futvan/z/system/zworkflow/ZworkflowAction.java. The manipulation of the argument tableId leads to sql injection. The attack can be launched… | |
| Analizada | Media (5.3) | 0.66% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. This issue affects some unknown processing of the file src/main/java/com/futvan/z/system/zfile/ZfileAction.upload. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The… | |
| Analizada | Media (5.3) | 0.36% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted… | |
| Analizada | Media (5.3) | 0.62% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in zj1983 zz up to 2024-08. Affected is the function GetUserOrg of the file com/futvan/z/framework/core/SuperZ.java. The manipulation of the argument userId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (8.1) | 0.42% | — | Exertio FrameworkAI | 1/3/2025 | 17/6/2026 | The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.1. This is due to the plugin not properly validating a user's identity prior to updating their password through the fl_forgot_pass_new() function. This makes it possible for… | |
| Aplazada | Alta (8.3) | 0.36% | — | Discord BOT Framework KernelAI | 18/2/2025 | 17/6/2026 | Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Because of the nature of arbitrary user-submited code execution, this allows user to execute potentially malicious code to perform damage or extract sensitive information. By… | |
| Aplazada | Media (5.4) | 0.16% | — | Intel GPAAIIntel GPA FrameworkAI | 12/2/2025 | 17/6/2026 | Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (8.5) | 0.36% | — | Opensecurity Mobile Security Framework | 5/2/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it should not be accepted. This issue has… | |
| Analizada | Media (4.8) | 0.46% | — | Opensecurity Mobile Security Framework | 5/2/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), and periods (.).… | |
| Analizada | Alta (8.4) | 0.39% | — | Opensecurity Mobile Security Framework | 5/2/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), and periods (.).… | |
| Analizada | Media (5.4) | 0.32% | — | Silverstripe Framework | 14/1/2025 | 17/6/2026 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HTML markup. This is an intentional feature, allowing links and other relevant HTML markup for the given message. Some form messages include content that the user can provide. There are scenarios in… | |
| Aplazada | Media (5.4) | 1.1% | 💥 Exploit | Silverstripe FrameworkAI | 14/1/2025 | 17/6/2026 | silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functionality, the linked oEmbed JSON includes an HTML attribute which will replace the embed shortcode. The HTML is not sanitized before replacing the shortcode, allowing a script payload to be executed on… | |
| Modificada | Alta (8.8) | 2.3% | — | Microsoft .netMicrosoft Visual Studio 2017Microsoft .net Framework | 14/1/2025 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Analizada | Media (6.6) | 0.37% | — | Boozallen Megamenu Framework | 9/1/2025 | 17/6/2026 | Vulnerability in Drupal Megamenu Framework.This issue affects Megamenu Framework: *.*. | |
| Analizada | Alta (7.8) | 0.19% | — | Dell Update Package Framework | 7/1/2025 | 17/6/2026 | Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary remote scripts on the server. Exploitation may lead to a denial of service by an attacker. | |
| Aplazada | Media (6.5) | 0.35% | — | Oqtane FrameworkAI | 20/12/2024 | 17/6/2026 | Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter. | |
| Aplazada | Alta (7.5) | 0.46% | — | Oqtane FrameworkAI | 20/12/2024 | 17/6/2026 | Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or access restricted data without proper authorization. The lack of server-side validation exacerbates the issue, as the… | |
| Aplazada | Media (4.3) | 0.29% | — | Oqtane FrameworkAI | 20/12/2024 | 17/6/2026 | An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to access inbox messages of other users by manipulating the notification ID in the request URL. By changing the notification ID, an attacker can view sensitive mail details belonging to other users. | |
| Aplazada | Media (5.4) | 0.59% | — | Apollo13themes Apollo13 Framework ExtensionsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Apollo13Themes Apollo13 Framework Extensions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apollo13 Framework Extensions: from n/a through 1.8.10. | |
| Analizada | Alta (7.5) | 0.41% | — | Opensecurity Mobile Security Framework | 3/12/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, the requests.get() request in the _check_url method is specified as allow_redirects=True, which allows a server-side request forgery when… | |
| Analizada | Media (5.4) | 0.52% | — | Opensecurity Mobile Security Framework | 3/12/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to upload files with scripts in the filename parameter. As a result, a malicious user can upload a script file to the system. When users… |