Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1294 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.9%—Syncfusion Nodejs File System Provider12/7/202317/6/2026
The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can: - On Windows, list files in any directory, read any file, delete any file, upload any file to any directory accessible by the web server. - On Linux, read any file,…
ModificadaAlta (7.5)35%—Adobe Coldfusion12/7/202317/6/2026
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the confidentiality…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitAdobe Coldfusion12/7/202317/6/2026
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitAdobe Coldfusion12/7/202317/6/2026
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation…
ModificadaAlta (7.3)0.16%—BD Alaris Infusion Central13/6/202317/6/2026
The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.
ModificadaMedia (5.4)0.65%—Theme-fusion Avada7/6/202317/6/2026
The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers, and above, to inject arbitrary web scripts in pages that…
ModificadaMedia (6.1)2.2%💥 ExploitSquarepiginteractive Fusioninvoice25/5/202317/6/2026
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details.
ModificadaMedia (6)0.37%—Vmware FusionVmware Workstation25/4/202317/6/2026
VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
ModificadaAlta (8.2)2.0%—Vmware FusionVmware Workstation25/4/202317/6/2026
VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
ModificadaAlta (8.8)0.87%💥 PoCVmware FusionVmware Workstation25/4/202317/6/2026
VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
ModificadaAlta (7.8)0.38%—Vmware Fusion25/4/202317/6/2026
VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system.
ModificadaMedia (5.3)1.0%—Sync Oxygen Content FusionSync Oxygen XML WEB Author14/4/202317/6/2026
A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714 and 23.1.1.4 build 2023021715 are also…
ModificadaMedia (4.9)59%—Adobe Coldfusion23/3/202317/6/2026
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in Arbitrary file system read. Exploitation of this issue does not require user interaction, but does…
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitAdobe Coldfusion23/3/202317/6/2026
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
AnalizadaCrítica (9.8)17%⚠ Explotación activaAdobe Coldfusion23/3/202317/6/2026
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
ModificadaAlta (8.1)0.65%—Php-fusion17/2/202317/6/2026
An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature.
ModificadaMedia (5.3)0.78%—Sitefusion Application Server31/1/202317/6/2026
A vulnerability, which was classified as problematic, was found in SiteFusion Application Server up to 6.6.6. This affects an unknown part of the file getextension.php of the component Extension Handler. The manipulation leads to path traversal. Upgrading to version 6.6.7 is able to address this issue. The identifier…
ModificadaAlta (7.5)1.0%—Rocketsoftware Trufusion Enterprise12/1/202317/6/2026
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
ModificadaAlta (7.5)24%—Rocketsoftware Trufusion Enterprise12/1/202317/6/2026
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProxy.
ModificadaAlta (8.2)1.1%💥 PoCVmware WorkstationVmware EsxiVmware Fusion14/12/202217/6/2026
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation…
ModificadaAlta (7.8)2.8%—HP FusionHP Support Assistant12/12/202217/6/2026
HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance Tune-up.
ModificadaCrítica (9.8)1.2%—Rocketsoftware Trufusion1/12/202217/6/2026
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.
ModificadaAlta (7.5)0.71%—Fusionauth28/11/202217/6/2026
FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve any file readable by the user running the FusionAuth process.
ModificadaCrítica (9.6)0.93%—Fusiondirectory22/11/20229/7/2026
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.
ModificadaCrítica (9.8)0.98%—Fusiondirectory22/11/20229/7/2026
Fusiondirectory 1.3 suffers from Improper Session Handling.
Orbitaley — Vulnerabilidades