Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.14% | — | HPE Data Management Framework SuiteAIHPE CxfsAI | 15/11/2024 | 17/6/2026 | A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access. | |
| Analizada | Alta (8.7) | 45% | 💥 PoC | Laravel FrameworkDebian Linux | 12/11/2024 | 17/6/2026 | Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23,… | |
| Analizada | Media (5.4) | 0.31% | — | Basticom Framework | 5/11/2024 | 17/6/2026 | The Basticom Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Media (5.3) | 0.51% | — | ASH Framework ASH PostgresAIAsh-rs ASHAI | 23/10/2024 | 17/6/2026 | AshPostgres is the PostgreSQL data layer for Ash Framework. Starting in version 2.0.0 and prior to version 2.4.10, in certain very specific situations, it was possible for the policies of an update action to be skipped. This occurred only on "empty" update actions (no changing fields), and would allow their hooks… | |
| Modificada | Media (5.3) | 0.62% | 💥 PoC | Vmware Spring Framework | 18/10/2024 | 17/6/2026 | The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected. | |
| Analizada | Media (4.3) | 0.44% | — | Oracle Enterprise Command Center Framework | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are ECC:11-13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Aplazada | Alta (7.8) | 0.18% | — | Lenovo Service FrameworkAI | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code with elevated privileges. | |
| Analizada | Alta (7.8) | 0.33% | — | Adobe Framemaker | 9/10/2024 | 17/6/2026 | Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.33% | — | Adobe Framemaker | 9/10/2024 | 17/6/2026 | Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.33% | — | Adobe Framemaker | 9/10/2024 | 17/6/2026 | Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file which can be automatically processed or executed by the system.… | |
| Analizada | Alta (7.8) | 0.35% | — | Adobe Framemaker | 9/10/2024 | 17/6/2026 | Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious path into the search directories, which the application could unknowingly execute. This could… | |
| Analizada | Alta (7.8) | 0.37% | — | Adobe Framemaker | 9/10/2024 | 17/6/2026 | Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.… | |
| Aplazada | Media (6.4) | 0.33% | — | Toolstack Auto IframeAI | 9/10/2024 | 17/6/2026 | The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web… | |
| Modificada | Alta (7.5) | 3.0% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 8/10/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | |
| Analizada | Alta (7.5) | 2.9% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 8/10/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | |
| Modificada | Media (5.1) | 0.22% | — | Catchthemes Full Frame | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchthemes Full frame full-frame allows Stored XSS.This issue affects Full frame: from n/a through <= 2.7.2. | |
| Aplazada | Alta (8.2) | 0.51% | — | Theupdateframework Go-tufAI | 1/10/2024 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", then the client should trace the delegations in the order "A" then "B" then "C" but it may incorrectly trace the… | |
| Aplazada | Alta (7.5) | 15% | 💥 Exploit | Apache TomcatAIEclipse JettyAIVmware FrameworkAI | 13/9/2024 | 17/6/2026 | Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.… | |
| Analizada | Media (4.3) | 0.57% | — | Vmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Oncommand Insight | 20/8/2024 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: | |
| Analizada | Crítica (9.8) | 0.96% | — | Opensecurity Mobile Security Framework | 19/8/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extraction of .a extension files, the measure intended to prevent… | |
| Analizada | Media (4.3) | 0.25% | — | SAP Shared Service Framework | 13/8/2024 | 17/6/2026 | SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application | |
| Analizada | Media (6.5) | 0.32% | — | SAP Shared Service Framework | 13/8/2024 | 17/6/2026 | SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On successful exploitation, an attacker can cause a high impact on confidentiality of the application. | |
| Analizada | Crítica (9.8) | 2.9% | 💥 PoC | Havocframework Havoc | 12/8/2024 | 17/6/2026 | An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server. | |
| Analizada | Crítica (9.5) | 1.4% | — | Microchip Advanced Software Framework | 8/8/2024 | 17/6/2026 | Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software… | |
| Analizada | Media (4.8) | 0.33% | — | Swiftideas Swift Framework | 1/8/2024 | 17/6/2026 | The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) |