Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.17% | — | Dell Update Package Framework | 1/3/2024 | 17/6/2026 | Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin. | |
| Aplazada | Alta (8.8) | 1.7% | — | Laurelbridge Dicom Connectivity FrameworkAI | 1/3/2024 | 17/6/2026 | Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file. | |
| Aplazada | Alta (8.1) | 4.0% | 💥 PoC | Vmware Spring FrameworkAI | 23/2/2024 | 17/6/2026 | Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing… | |
| Analizada | Alta (7.5) | 0.99% | — | Honeywell Niagara Framework | 13/2/2024 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara 4.1. | |
| Modificada | Media (5.4) | 0.32% | — | Apollo13themes Apollo13 Framework Extensions | 8/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions allows Stored XSS.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.2. | |
| Modificada | Alta (7.1) | 0.17% | — | Dell Update Package Framework | 6/2/2024 | 17/6/2026 | DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service | |
| Modificada | Media (4.3) | 0.36% | — | Silverstripe Framework | 23/1/2024 | 17/6/2026 | Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` using the `GridFieldAddExistingAutocompleter` component, the record's title can be… | |
| Modificada | Alta (7.5) | 1.0% | — | Vmware Spring Framework | 22/1/2024 | 17/6/2026 | In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: Typically, Spring Boot applications need the… | |
| Modificada | Crítica (9.6) | 0.55% | — | Chromiumembedded Chromium Embedded Framework | 13/1/2024 | 17/6/2026 | Chromium Embedded Framework (CEF) is a simple framework for embedding Chromium-based browsers in other applications.`CefVideoConsumerOSR::OnFrameCaptured` does not check `pixel_format` properly, which leads to out-of-bounds read out of the sandbox. This vulnerability was patched in commit 1f55d2e. | |
| Modificada | Crítica (9.6) | 0.70% | — | Chromiumembedded Chromium Embedded Framework | 12/1/2024 | 17/6/2026 | CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. `CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory` does not check the size of the shared memory, which leads to out-of-bounds read outside the sandbox. This vulnerability was patched in commit… | |
| Modificada | Media (6.5) | 0.59% | — | Pimcore Customer Management Framework | 11/1/2024 | 17/6/2026 | pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data extraction feature and query over the information returned, leading to customer data exposure. Permissions are not enforced when reaching… | |
| Modificada | Media (6.5) | 0.56% | — | Pimcore Customer Management Framework | 11/1/2024 | 17/6/2026 | The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access the list of potential duplicate users and see their data. Permissions are enforced when reaching the… | |
| Modificada | Media (4.3) | 0.49% | — | Pimcore E-commerce Framework | 11/1/2024 | 17/6/2026 | ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has been patched in version 1.0.10. | |
| Modificada | Alta (7.5) | 3.6% | — | Microsoft .net Framework | 9/1/2024 | 17/6/2026 | .NET Framework Denial of Service Vulnerability | |
| Modificada | Crítica (9.8) | 2.8% | — | Microsoft PowershellMicrosoft Visual Studio 2022Microsoft .net FrameworkMicrosoft .net | 9/1/2024 | 17/6/2026 | NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability | |
| Modificada | Alta (8.7) | 1.2% | — | Microsoft.data.sqlclientMicrosoft SQL ServerMicrosoft System.data.sqlclientMicrosoft Visual Studio 2022+2 | 9/1/2024 | 17/6/2026 | Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | |
| Modificada | Crítica (9.1) | 0.61% | — | SAP Application Interface Framework | 9/1/2024 | 17/6/2026 | In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and execute OS commands directly. By this, such user can control the behaviour of the application. This leads to considerable impact on confidentiality, integrity and… | |
| Modificada | Alta (8.8) | 0.22% | — | Apollo13themes Apollo13 Framework Extensions | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Apollo13Themes Apollo13 Framework Extensions.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.1. | |
| Modificada | Alta (8.8) | 0.49% | — | Yiiframework Yii2-authclient | 22/12/2023 | 17/6/2026 | yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE implementation is vulnerable in 2 ways. First, the `authCodeVerifier` should be removed after usage (similar to `authState`). Second, there… | |
| Modificada | Crítica (9.8) | 0.72% | — | Yiiframework Yii2-authclient | 22/12/2023 | 17/6/2026 | yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth1/2 `state` and OpenID Connect `nonce` is vulnerable for a `timing attack` since it is compared via regular string comparison (instead of… | |
| Modificada | Alta (8.2) | 0.46% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Carbon Identity Application Authentication Endpoint+1 | 15/12/2023 | 17/6/2026 | Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: Attacker should have: When all preconditions are met, a malicious actor could use JIT provisioning… | |
| Modificada | Alta (7.5) | 1.2% | — | Vmware Spring Framework | 28/11/2023 | 17/6/2026 | In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: Typically, Spring Boot applications need the… | |
| Modificada | Crítica (9.8) | 3.1% | — | Yiiframework YII | 14/11/2023 | 17/6/2026 | Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. An attacker may leverage this vulnerability to compromise the host system. A fix has been developed for the 1.1.29 release. Users… | |
| Modificada | Crítica (9.8) | 13% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 14/11/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 2.9% | — | Microsoft .net Framework | 14/11/2023 | 17/6/2026 | ASP.NET Security Feature Bypass Vulnerability |