Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.51% | — | Theme-fusion Avada | 27/10/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation. | |
| Modificada | Alta (7.5) | 36% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction. | |
| Modificada | Alta (7.5) | 34% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction. | |
| Modificada | Alta (7.2) | 45% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary file system write. Exploitation of this issue does not require user interaction, but does require… | |
| Modificada | Media (4.9) | 45% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require user interaction, but does require… | |
| Modificada | Alta (7.5) | 44% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require user interaction. | |
| Modificada | Alta (7.2) | 79% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user… | |
| Modificada | Alta (7.5) | 44% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services. Exploitation of this issue does not require user interaction. | |
| Modificada | Alta (7.5) | 53% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction. | |
| Modificada | Crítica (9.8) | 80% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user… | |
| Modificada | Crítica (9.8) | 37% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a… | |
| Modificada | Crítica (9.8) | 73% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a… | |
| Modificada | Crítica (9.8) | 43% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a… | |
| Modificada | Crítica (9.8) | 72% | — | Adobe Coldfusion | 14/10/2022 | 17/6/2026 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a… | |
| Modificada | Alta (7.8) | 0.97% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+15 | 7/10/2022 | 17/6/2026 | A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.97% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+15 | 7/10/2022 | 17/6/2026 | A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code. | |
| Modificada | Alta (7.8) | 1.0% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+15 | 7/10/2022 | 17/6/2026 | A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.97% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+15 | 7/10/2022 | 17/6/2026 | A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Image Processing component. | |
| Modificada | Alta (7.8) | 0.97% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+15 | 7/10/2022 | 17/6/2026 | A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code. | |
| Modificada | Media (6.1) | 0.66% | — | Glfusion | 29/9/2022 | 17/6/2026 | glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. This input was echoed unmodified in the application's response. | |
| Modificada | Media (6.5) | 0.93% | — | Fusionpbx | 29/9/2022 | 17/6/2026 | An issue was discovered in FusionPBX before 4.5.30. The log_viewer.php Log View page allows an authenticated user to choose an arbitrary filename for download (i.e., not necessarily freeswitch.log in the intended directory). | |
| Modificada | Alta (8.8) | 0.88% | — | Php-fusion Phpfusion | 7/9/2022 | 17/6/2026 | Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20. | |
| Modificada | Crítica (9.8) | 1.8% | — | Fusionpbx | 18/8/2022 | 17/6/2026 | FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php. | |
| Modificada | Alta (7.8) | 0.21% | — | Autodesk Fusion 360 | 29/7/2022 | 17/6/2026 | An attacker can force the victim’s device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360’s document parser. The vulnerability exists in the application’s ‘Insert SVG’ procedure. An attacker can also leverage this vulnerability to obtain victim’s public IP and… | |
| Modificada | Media (6.1) | 0.76% | — | Fusionpbx | 1/7/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web script or HTML via an unsanitized "path" parameter in resources/login.php. |