Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1099 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.17%—Dell Update Package Framework1/3/202417/6/2026
Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin.
AplazadaAlta (8.8)1.7%—Laurelbridge Dicom Connectivity FrameworkAI1/3/202417/6/2026
Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file.
AplazadaAlta (8.1)4.0%💥 PoCVmware Spring FrameworkAI23/2/202417/6/2026
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing…
AnalizadaAlta (7.5)0.99%—Honeywell Niagara Framework13/2/202417/6/2026
Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara 4.1.
ModificadaMedia (5.4)0.32%—Apollo13themes Apollo13 Framework Extensions8/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions allows Stored XSS.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.2.
ModificadaAlta (7.1)0.17%—Dell Update Package Framework6/2/202417/6/2026
DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service
ModificadaMedia (4.3)0.36%—Silverstripe Framework23/1/202417/6/2026
Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` using the `GridFieldAddExistingAutocompleter` component, the record's title can be…
ModificadaAlta (7.5)1.0%—Vmware Spring Framework22/1/202417/6/2026
In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: Typically, Spring Boot applications need the…
ModificadaCrítica (9.6)0.55%—Chromiumembedded Chromium Embedded Framework13/1/202417/6/2026
Chromium Embedded Framework (CEF) is a simple framework for embedding Chromium-based browsers in other applications.`CefVideoConsumerOSR::OnFrameCaptured` does not check `pixel_format` properly, which leads to out-of-bounds read out of the sandbox. This vulnerability was patched in commit 1f55d2e.
ModificadaCrítica (9.6)0.70%—Chromiumembedded Chromium Embedded Framework12/1/202417/6/2026
CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. `CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory` does not check the size of the shared memory, which leads to out-of-bounds read outside the sandbox. This vulnerability was patched in commit…
ModificadaMedia (6.5)0.59%—Pimcore Customer Management Framework11/1/202417/6/2026
pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data extraction feature and query over the information returned, leading to customer data exposure. Permissions are not enforced when reaching…
ModificadaMedia (6.5)0.56%—Pimcore Customer Management Framework11/1/202417/6/2026
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access the list of potential duplicate users and see their data. Permissions are enforced when reaching the…
ModificadaMedia (4.3)0.49%—Pimcore E-commerce Framework11/1/202417/6/2026
ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has been patched in version 1.0.10.
ModificadaAlta (7.5)3.6%—Microsoft .net Framework9/1/202417/6/2026
.NET Framework Denial of Service Vulnerability
ModificadaCrítica (9.8)2.8%—Microsoft PowershellMicrosoft Visual Studio 2022Microsoft .net FrameworkMicrosoft .net9/1/202417/6/2026
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
ModificadaAlta (8.7)1.2%—Microsoft.data.sqlclientMicrosoft SQL ServerMicrosoft System.data.sqlclientMicrosoft Visual Studio 2022+29/1/202417/6/2026
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
ModificadaCrítica (9.1)0.61%—SAP Application Interface Framework9/1/202417/6/2026
In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and execute OS commands directly. By this, such user can control the behaviour of the application. This leads to considerable impact on confidentiality, integrity and…
ModificadaAlta (8.8)0.22%—Apollo13themes Apollo13 Framework Extensions5/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Apollo13Themes Apollo13 Framework Extensions.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.1.
ModificadaAlta (8.8)0.49%—Yiiframework Yii2-authclient22/12/202317/6/2026
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE implementation is vulnerable in 2 ways. First, the `authCodeVerifier` should be removed after usage (similar to `authState`). Second, there…
ModificadaCrítica (9.8)0.72%—Yiiframework Yii2-authclient22/12/202317/6/2026
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth1/2 `state` and OpenID Connect `nonce` is vulnerable for a `timing attack` since it is compared via regular string comparison (instead of…
ModificadaAlta (8.2)0.46%—Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Carbon Identity Application Authentication Endpoint+115/12/202317/6/2026
Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: Attacker should have: When all preconditions are met, a malicious actor could use JIT provisioning…
ModificadaAlta (7.5)1.2%—Vmware Spring Framework28/11/202317/6/2026
In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: Typically, Spring Boot applications need the…
ModificadaCrítica (9.8)3.1%—Yiiframework YII14/11/202317/6/2026
Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. An attacker may leverage this vulnerability to compromise the host system. A fix has been developed for the 1.1.29 release. Users…
ModificadaCrítica (9.8)13%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 202214/11/202317/6/2026
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
ModificadaAlta (8.8)2.9%—Microsoft .net Framework14/11/202317/6/2026
ASP.NET Security Feature Bypass Vulnerability
Orbitaley — Vulnerabilidades