Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 1.3% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 9/7/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | |
| Aplazada | Baja (2.1) | 1.1% | 💥 PoC | DjangorestframeworkAI | 26/6/2024 | 17/6/2026 | Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags. | |
| Modificada | Alta (7) | 0.19% | — | Aveva PI Asset Framework Client | 12/6/2024 | 17/6/2026 | There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker. | |
| Modificada | Alta (7.8) | 0.24% | — | Amazon AWS Deployment Framework | 11/6/2024 | 17/6/2026 | The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined in AWS Organizations while taking… | |
| Modificada | Alta (7.5) | 0.78% | 💥 PoC | Ninjaframework Ninja | 6/6/2024 | 17/6/2026 | The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information. | |
| Analizada | Media (4.7) | 0.35% | — | Yiiframework YII | 30/5/2024 | 17/6/2026 | Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a Cross-site Scripting (XSS) vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). This issue lies in the mechanism for displaying function… | |
| Analizada | Media (6.5) | 0.33% | — | Swiftideas Swift Framework | 17/5/2024 | 17/6/2026 | The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Analizada | Alta (7.8) | 0.18% | — | Intel Graphics Performance Analyzers Framework | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.21% | — | Intel Graphics Performance Analyzers Framework | 16/5/2024 | 17/6/2026 | Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.20% | — | Intel Graphics Performance Analyzers Framework | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.4) | 0.36% | — | Swiftideas Swift FrameworkAI | 14/5/2024 | 17/6/2026 | The Swift Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 2.7.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.38% | — | Swiftideas Swift FrameworkAI | 14/5/2024 | 17/6/2026 | The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sf_edit_directory_item() function in all versions up to, and including, 2.7.31. This makes it possible for unauthenticated attackers to update arbitrary posts with arbitrary content.… | |
| Aplazada | Baja (2.8) | 0.15% | — | Motorola FrameworkAI | 3/5/2024 | 17/6/2026 | An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data. | |
| Analizada | Alta (7.4) | 0.38% | — | Adive Framework | 30/4/2024 | 17/6/2026 | Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user. | |
| Analizada | Alta (7.4) | 0.38% | — | Adive Framework | 30/4/2024 | 17/6/2026 | Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/tables/add, in multiple parameters. An attacker could retrieve the session details of an authenticated user. | |
| Aplazada | Sin puntuar | 1.3% | 💥 Exploit | Laravel FrameworkAI | 16/4/2024 | 17/6/2026 | An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed by multiple third parties because the owner of a Laravel Framework installation can choose to have debugging logs, but needs to set the access control… | |
| Analizada | Media (6.5) | 0.51% | — | Oracle Applications Framework | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: REST Services). Supported versions that are affected are 12.2.9-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Aplazada | Alta (8.1) | 1.2% | 💥 PoC | Vmware FrameworkAI | 16/4/2024 | 17/6/2026 | Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing… | |
| Modificada | Alta (7.3) | 2.5% | 💥 PoC | Microsoft .net FrameworkMicrosoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 9/4/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Aplazada | Alta (8.5) | 0.50% | — | Sizam Rehub FrameworkAI | 7/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sizam REHub Framework.This issue affects REHub Framework: from n/a before 19.6.2. | |
| Analizada | Media (4.3) | 0.51% | — | Opensecurity Mobile Security Framework | 4/4/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the organization’s infrastructure. When a… | |
| Analizada | Alta (7.5) | 99% | ⚠ Explotación activa💥 Exploit | Microsoft .net Framework | 23/3/2024 | 17/6/2026 | .NET Framework Information Disclosure Vulnerability | |
| Analizada | Alta (7.5) | 0.72% | — | Opensecurity Mobile Security Framework | 22/3/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In version 3.9.5 Beta and prior, MobSF does not perform any input validation when extracting the hostnames in `android:host`, so requests can also be sent to local… | |
| Aplazada | Media (5.5) | 0.80% | 💥 Exploit | Djangorestframework-simplejwtAI | 16/3/2024 | 17/6/2026 | djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method. | |
| Analizada | Alta (8.1) | 2.6% | — | Vmware Spring FrameworkNetapp Active IQ Unified Manager | 16/3/2024 | 17/6/2026 | Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is… |