Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.21% | — | Tinywebgallery Advanced Iframe | 26/3/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due to insufficient input sanitization and output escaping on user supplied attributes through the 'src' attribute when the src supplied… | |
| Modificada | Media (5.4) | 0.26% | — | Tinywebgallery Advanced Iframe | 26/3/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Media (5.3) | 0.66% | — | Yiiframework YII | 24/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.62% | — | Yiiframework YII | 24/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to… | |
| Aplazada | Alta (7.2) | 31% | 💥 PoC | Horde IMPAIHorde Application FrameworkAI | 21/3/2025 | 17/6/2026 | Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025. | |
| Analizada | Crítica (9.1) | 80% | — | Yiiframework YII | 20/3/2025 | 17/6/2026 | In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a valid Behavior class name or configuration. This allows an attacker to instantiate arbitrary classes, passing parameters to their constructors and invoking… | |
| Aplazada | Media (6.9) | 0.48% | — | Viames Pair FrameworkAI | 17/3/2025 | 17/6/2026 | A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical. Affected by this vulnerability is the function getCookieContent of the file /src/UserRemember.php of the component PHP Object Handler. The manipulation of the argument cookieName leads to deserialization. The attack can be… | |
| Aplazada | Alta (8.6) | 0.33% | — | Freshface Fresh FrameworkAI | 15/3/2025 | 17/6/2026 | Missing Authorization vulnerability in FRESHFACE Fresh Framework fresh-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Fresh Framework: from n/a through <= 1.70.0. | |
| Aplazada | Crítica (10) | 0.50% | — | Freshface Fresh FrameworkAI | 10/3/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Fresh Framework fresh-framework allows Code Injection.This issue affects Fresh Framework: from n/a through <= 1.70.0. | |
| Analizada | Media (6.1) | 0.53% | — | Laravel Framework | 10/3/2025 | 17/6/2026 | The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page. | |
| Analizada | Media (6.1) | 0.60% | — | Laravel Framework | 10/3/2025 | 17/6/2026 | The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page. | |
| Aplazada | Alta (7.5) | 0.38% | — | CS FrameworkAI | 7/3/2025 | 17/6/2026 | The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via the get_widget_settings_json() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can… | |
| Aplazada | Alta (8.8) | 0.90% | — | CS FrameworkAI | 7/3/2025 | 17/6/2026 | The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cs_widget_file_delete() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary… | |
| Analizada | Media (6.9) | 0.75% | 💥 PoC | Laravel Framework | 5/3/2025 | 17/6/2026 | Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1. | |
| Analizada | Media (5.3) | 0.53% | — | Zframeworks ZZ | 3/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in zj1983 zz up to 2024-8. Affected by this vulnerability is an unknown functionality of the file /import_data_todb. The manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.53% | — | Zframeworks ZZ | 3/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in zj1983 zz up to 2024-8. Affected is an unknown function of the file /import_data_check. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.3) | 0.53% | — | Zframeworks ZZ | 3/3/2025 | 17/6/2026 | A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this… | |
| Analizada | Media (5.3) | 0.63% | — | Zframeworks ZZ | 3/3/2025 | 17/6/2026 | A vulnerability was found in zj1983 zz up to 2024-8. It has been declared as problematic. This vulnerability affects the function deleteLocalFile of the file src/main/java/com/futvan/z/system/zfile/ZfileAction.java of the component File Handler. The manipulation of the argument zids leads to denial of service. The… | |
| Analizada | Media (5.3) | 0.55% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in zj1983 zz up to 2024-8. This affects an unknown part of the file /resolve. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (5.3) | 0.53% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. Affected by this issue is the function sendNotice of the file src/main/java/com/futvan/z/erp/customer_notice/Customer_noticeAction.java of the component HTTP Request Handler. The manipulation of the argument url leads to… | |
| Analizada | Media (5.3) | 0.54% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in zj1983 zz up to 2024-8. Affected by this vulnerability is the function getUserList of the file src/main/java/com/futvan/z/system/zrole/ZroleAction.java. The manipulation of the argument roleid leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (5.3) | 0.57% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in zj1983 zz up to 2024-8. Affected is the function GetDBUser of the file src/main/java/com/futvan/z/system/zorg/ZorgAction.java. The manipulation of the argument user_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (4.8) | 0.40% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as problematic. This issue affects some unknown processing of the component Customer Information Handler. The manipulation of the argument Customer Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability was found in zj1983 zz up to 2024-8 and classified as critical. Affected by this issue is the function getUserOrgForUserId of the file src/main/java/com/futvan/z/system/zorg/ZorgAction.java. The manipulation of the argument userID leads to sql injection. The attack may be launched remotely. The exploit… | |
| Analizada | Media (5.3) | 0.54% | — | Zframeworks ZZ | 2/3/2025 | 17/6/2026 | A vulnerability has been found in zj1983 zz up to 2024-8 and classified as critical. Affected by this vulnerability is the function getOaWid of the file src/main/java/com/futvan/z/system/zworkflow/ZworkflowAction.java. The manipulation of the argument tableId leads to sql injection. The attack can be launched… |