Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1296 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.21%—Autodesk Fusion 36029/7/202217/6/2026
An attacker can force the victim’s device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360’s document parser. The vulnerability exists in the application’s ‘Insert SVG’ procedure. An attacker can also leverage this vulnerability to obtain victim’s public IP and…
ModificadaMedia (6.1)0.76%—Fusionpbx1/7/202217/6/2026
Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web script or HTML via an unsanitized "path" parameter in resources/login.php.
ModificadaCrítica (9.8)71%💥 ExploitFusion Builder Project Fusion BuilderTheme-fusion Avada16/5/202217/6/2026
The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network…
ModificadaMedia (6.1)45%—Adobe Coldfusion12/5/202217/6/2026
ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
ModificadaCrítica (9.8)1.5%—Fusionpbx4/5/202217/6/2026
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
ModificadaAlta (7.2)1.6%—Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+6430/3/202217/6/2026
A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in…
ModificadaAlta (7.2)1.6%—Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+6430/3/202217/6/2026
A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in…
ModificadaMedia (6.1)0.81%—Php-fusion Phpfusion17/2/202217/6/2026
A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel.
ModificadaAlta (7.5)1.1%—Vmware FusionVmware Esxi16/2/202217/6/2026
VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.
ModificadaMedia (6.7)0.57%—Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi16/2/202217/6/2026
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
ModificadaMedia (6.7)0.73%—Vmware Cloud FoundationVmware FusionVmware Workstation PlayerVmware Workstation PRO+116/2/202217/6/2026
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
ModificadaAlta (7.8)4.7%—Vmware Cloud FoundationVmware WorkstationVmware FusionVmware Esxi4/1/202217/6/2026
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this…
ModificadaMedia (4.3)0.36%—Glfusion14/12/202117/6/2026
glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.
ModificadaCrítica (9.8)1.2%—Glfusion14/12/202117/6/2026
glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.
ModificadaMedia (5.3)0.73%—Glfusion14/12/202117/6/2026
glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox of any user. When users want to register, they will find that the mailbox has been occupied.
ModificadaCrítica (9.1)0.53%—Glfusion14/12/202117/6/2026
glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attacker can complete the attack remotely without interaction.
ModificadaAlta (7.5)81%💥 PoCApache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+4214/12/202117/6/2026
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in…
ModificadaAlta (8.8)0.95%—Huawei Fusioncompute23/11/202117/6/2026
There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the…
ModificadaMedia (5.5)0.17%—Huawei Ecns280 TD FirmwareHuawei Fusioncompute23/11/202117/6/2026
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause the information leak.
ModificadaAlta (8.8)0.97%—Fusionpbx5/11/202117/6/2026
An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values).
ModificadaAlta (8.8)36%💥 ExploitFusionpbx5/11/202117/6/2026
An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).
ModificadaAlta (8.8)0.97%—Fusionpbx5/11/202117/6/2026
An issue was discovered in FusionPBX before 4.5.30. The FAX file name may have risky characters.
ModificadaCrítica (9.6)1.6%—Php-fusion Phpfusion2/11/202117/6/2026
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.
ModificadaMedia (6.5)4.6%—Apache MinaOracle Banking PaymentsOracle Banking Trade Finance Process ManagementOracle Banking Treasury Management+51/11/202117/6/2026
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
ModificadaAlta (7.5)0.86%—Huawei Fusioncube Firmware27/10/202117/6/2026
There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname.…