Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 493 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.39% | — | Apollo13themes Apollo13 Framework Extensions | 8/11/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Apollo13Themes Apollo13 Framework Extensions plugin <= 1.9.0 versions. | |
| Modificada | Media (6.1) | 0.35% | — | Oracle Enterprise Command Center Framework | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: UI Components). Supported versions that are affected are ECC: 8, 9 and 10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Command… | |
| Modificada | Media (6.5) | 0.51% | — | Oracle Enterprise Command Center Framework | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: API). Supported versions that are affected are ECC: 8, 9 and 10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.5) | 0.86% | — | Opensecurity Mobile Security Framework | 21/9/2023 | 17/6/2026 | Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy… | |
| Modificada | Crítica (9.8) | 0.88% | — | Yiiframework YII | 21/9/2023 | 17/6/2026 | web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter. | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+1 | 12/9/2023 | 17/6/2026 | Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+1 | 12/9/2023 | 17/6/2026 | Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+1 | 12/9/2023 | 17/6/2026 | Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+1 | 12/9/2023 | 17/6/2026 | Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.0% | — | Microsoft .net Framework | 12/9/2023 | 17/6/2026 | .NET Framework Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 1.4% | — | Weblogic-framework Project Weblogic-framework | 25/8/2023 | 17/6/2026 | weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a deserialization vulnerability which may lead to remote code execution. When weblogic-framework gets the command echo, it directly deserializes the data returned by the… | |
| Modificada | Alta (8.8) | 77% | 💥 PoC | Microsoft .net Framework | 8/8/2023 | 10/8/2026 | ASP.NET Elevation of Privilege Vulnerability | |
| Modificada | Media (5.9) | 1.5% | — | Microsoft .net Framework | 8/8/2023 | 10/8/2026 | .NET Framework Spoofing Vulnerability | |
| Analizada | Media (5.4) | 0.61% | — | Pimcore Customer Management Framework | 3/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2. | |
| Modificada | Media (6.1) | 0.40% | — | Yiiframework YII | 28/7/2023 | 17/6/2026 | Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this is disputed by the vendor because the cve-2022-31454-8e8555c31fd3 page does not describe why /books has a relationship to Yii 2. | |
| Modificada | Media (6.1) | 0.42% | — | Oracle Applications Framework | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.3-12.3.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Modificada | Media (6.5) | 0.54% | — | Pimcore Customer Management Framework | 10/7/2023 | 17/6/2026 | Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1. | |
| Modificada | Alta (7.5) | 2.2% | — | Microsoft .net Framework | 14/6/2023 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 2.6% | — | Microsoft .net FrameworkMicrosoft .net | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.8) | 0.90% | — | Microsoft .net Framework | 14/6/2023 | 17/6/2026 | .NET Framework Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 1.6% | — | Microsoft .net FrameworkMicrosoft .net | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual StudioMicrosoft Visual Studio 2017+2 | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.1% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Media (6.1) | 0.46% | — | Woocommerce Wooframework Tweaks | 5/6/2023 | 17/6/2026 | A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by this vulnerability is the function admin_screen_logic of the file wooframework-tweaks.php. The manipulation of the argument url leads to open redirect. The attack can be launched remotely. Upgrading… |