Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.35% | — | Data443 Risk Mitigation INC Lgpd FrameworkAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Mitigation, Inc. LGPD Framework lgpd-framework allows Reflected XSS.This issue affects LGPD Framework: from n/a through <= 2.0.2. | |
| Aplazada | Media (5.5) | 0.14% | — | HPE Data Management Framework SuiteAIHPE CxfsAI | 15/11/2024 | 17/6/2026 | A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access. | |
| Analizada | Alta (8.7) | 45% | 💥 PoC | Laravel FrameworkDebian Linux | 12/11/2024 | 17/6/2026 | Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23,… | |
| Analizada | Media (5.4) | 0.31% | — | Basticom Framework | 5/11/2024 | 17/6/2026 | The Basticom Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Media (5.3) | 0.51% | — | ASH Framework ASH PostgresAIAsh-rs ASHAI | 23/10/2024 | 17/6/2026 | AshPostgres is the PostgreSQL data layer for Ash Framework. Starting in version 2.0.0 and prior to version 2.4.10, in certain very specific situations, it was possible for the policies of an update action to be skipped. This occurred only on "empty" update actions (no changing fields), and would allow their hooks… | |
| Modificada | Media (5.3) | 0.62% | 💥 PoC | Vmware Spring Framework | 18/10/2024 | 17/6/2026 | The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected. | |
| Analizada | Media (4.3) | 0.44% | — | Oracle Enterprise Command Center Framework | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are ECC:11-13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Aplazada | Alta (7.8) | 0.18% | — | Lenovo Service FrameworkAI | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code with elevated privileges. | |
| Modificada | Alta (7.5) | 3.0% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 8/10/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | |
| Analizada | Alta (7.5) | 2.9% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 8/10/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | |
| Aplazada | Alta (8.2) | 0.51% | — | Theupdateframework Go-tufAI | 1/10/2024 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", then the client should trace the delegations in the order "A" then "B" then "C" but it may incorrectly trace the… | |
| Aplazada | Alta (7.5) | 15% | 💥 Exploit | Apache TomcatAIEclipse JettyAIVmware FrameworkAI | 13/9/2024 | 17/6/2026 | Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.… | |
| Analizada | Media (4.3) | 0.57% | — | Vmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Oncommand Insight | 20/8/2024 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: | |
| Analizada | Crítica (9.8) | 0.96% | — | Opensecurity Mobile Security Framework | 19/8/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extraction of .a extension files, the measure intended to prevent… | |
| Analizada | Media (4.3) | 0.25% | — | SAP Shared Service Framework | 13/8/2024 | 17/6/2026 | SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application | |
| Analizada | Media (6.5) | 0.32% | — | SAP Shared Service Framework | 13/8/2024 | 17/6/2026 | SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On successful exploitation, an attacker can cause a high impact on confidentiality of the application. | |
| Analizada | Crítica (9.8) | 2.9% | 💥 PoC | Havocframework Havoc | 12/8/2024 | 17/6/2026 | An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server. | |
| Analizada | Crítica (9.5) | 1.4% | — | Microchip Advanced Software Framework | 8/8/2024 | 17/6/2026 | Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software… | |
| Analizada | Media (4.8) | 0.33% | — | Swiftideas Swift Framework | 1/8/2024 | 17/6/2026 | The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (5.4) | 1.0% | 💥 Exploit | Opensecurity Mobile Security Framework | 31/7/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5. | |
| Aplazada | Alta (7.2) | 1.0% | — | Redux FrameworkAI | 23/7/2024 | 17/6/2026 | The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct… | |
| Modificada | Media (5.4) | 0.31% | — | Apollo13themes Apollo13 Framework Extensions | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions apollo13-framework-extensions allows Stored XSS.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.3. | |
| Analizada | Media (5.4) | 0.35% | — | Silverstripe Framework | 17/7/2024 | 17/6/2026 | Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The… | |
| Analizada | Media (6.1) | 0.42% | — | Swiftideas Swift Framework | 13/7/2024 | 17/6/2026 | The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Media (4.8) | 0.37% | — | Swiftideas Swift Framework | 12/7/2024 | 17/6/2026 | The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) |