Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.12% | — | GoframeAI | 31/7/2024 | 17/6/2026 | goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-middle attack via the gclient component. | |
| Analizada | Media (5.4) | 1.0% | 💥 Exploit | Opensecurity Mobile Security Framework | 31/7/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5. | |
| Aplazada | Alta (7.2) | 1.0% | — | Redux FrameworkAI | 23/7/2024 | 17/6/2026 | The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct… | |
| Modificada | Media (5.4) | 0.31% | — | Apollo13themes Apollo13 Framework Extensions | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions apollo13-framework-extensions allows Stored XSS.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.3. | |
| Analizada | Media (5.4) | 0.35% | — | Silverstripe Framework | 17/7/2024 | 17/6/2026 | Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The… | |
| Analizada | Media (6.1) | 0.42% | — | Swiftideas Swift Framework | 13/7/2024 | 17/6/2026 | The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Media (4.8) | 0.37% | — | Swiftideas Swift Framework | 12/7/2024 | 17/6/2026 | The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.3) | 1.3% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 9/7/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Media (6.3) | 1.1% | 💥 PoC | Admiror-design-studio Admirorframes | 28/6/2024 | 17/6/2026 | Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML. This issue affects AdmirorFrames: before 5.0. | |
| Modificada | Alta (8.2) | 1.2% | 💥 PoC | Admiror-design-studio Admirorframes | 28/6/2024 | 17/6/2026 | Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This issue affects AdmirorFrames: before 5.0. | |
| Modificada | Media (6.3) | 1.5% | 💥 PoC | Admiror-design-studio Admirorframes | 28/6/2024 | 17/6/2026 | Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects AdmirorFrames: before 5.0. | |
| Aplazada | Baja (2.1) | 1.1% | 💥 PoC | DjangorestframeworkAI | 26/6/2024 | 17/6/2026 | Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags. | |
| Modificada | Crítica (9.8) | 0.73% | — | Adobe Framemaker Publishing Server | 13/6/2024 | 17/6/2026 | Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker could exploit this vulnerability to gain access to sensitive information which may include system or user privileges. Exploitation… | |
| Modificada | Crítica (9.8) | 1.1% | — | Adobe Framemaker Publishing Server | 13/6/2024 | 17/6/2026 | Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within the application. Exploitation of this issue… | |
| Modificada | Alta (7) | 0.19% | — | Aveva PI Asset Framework Client | 12/6/2024 | 17/6/2026 | There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker. | |
| Modificada | Alta (7.8) | 0.24% | — | Amazon AWS Deployment Framework | 11/6/2024 | 17/6/2026 | The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined in AWS Organizations while taking… | |
| Modificada | Alta (7.5) | 0.78% | 💥 PoC | Ninjaframework Ninja | 6/6/2024 | 17/6/2026 | The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information. | |
| Analizada | Media (4.7) | 0.35% | — | Yiiframework YII | 30/5/2024 | 17/6/2026 | Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a Cross-site Scripting (XSS) vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). This issue lies in the mechanism for displaying function… | |
| Aplazada | Media (6.4) | 0.34% | — | Tinywebgallery Advanced IframeAI | 23/5/2024 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_iframe_url_as_param_direct’ parameter in versions up to, and including, 2024.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Analizada | Alta (7.5) | 0.46% | — | Luckyframeweb | 23/5/2024 | 17/6/2026 | LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload method. | |
| Aplazada | Media (5) | 0.40% | — | IframeAI | 23/5/2024 | 17/6/2026 | The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to and including 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above… | |
| Analizada | Media (6.5) | 0.33% | — | Swiftideas Swift Framework | 17/5/2024 | 17/6/2026 | The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Analizada | Alta (7.8) | 0.18% | — | Intel Graphics Performance Analyzers Framework | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.21% | — | Intel Graphics Performance Analyzers Framework | 16/5/2024 | 17/6/2026 | Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.20% | — | Intel Graphics Performance Analyzers Framework | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. |