Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

1339 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.12%—GoframeAI31/7/202417/6/2026
goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-middle attack via the gclient component.
AnalizadaMedia (5.4)1.0%💥 ExploitOpensecurity Mobile Security Framework31/7/202417/6/2026
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5.
AplazadaAlta (7.2)1.0%—Redux FrameworkAI23/7/202417/6/2026
The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in versions 4.4.12 to 4.4.17. This makes it possible for unauthenticated attackers to upload JSON files, which can be used to conduct…
ModificadaMedia (5.4)0.31%—Apollo13themes Apollo13 Framework Extensions21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions apollo13-framework-extensions allows Stored XSS.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.3.
AnalizadaMedia (5.4)0.35%—Silverstripe Framework17/7/202417/6/2026
Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The…
AnalizadaMedia (6.1)0.42%—Swiftideas Swift Framework13/7/202417/6/2026
The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AnalizadaMedia (4.8)0.37%—Swiftideas Swift Framework12/7/202417/6/2026
The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (7.3)1.3%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 20229/7/202417/6/2026
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
ModificadaMedia (6.3)1.1%💥 PoCAdmiror-design-studio Admirorframes28/6/202417/6/2026
Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML. This issue affects AdmirorFrames: before 5.0.
ModificadaAlta (8.2)1.2%💥 PoCAdmiror-design-studio Admirorframes28/6/202417/6/2026
Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This issue affects AdmirorFrames: before 5.0.
ModificadaMedia (6.3)1.5%💥 PoCAdmiror-design-studio Admirorframes28/6/202417/6/2026
Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects AdmirorFrames: before 5.0.
AplazadaBaja (2.1)1.1%💥 PoCDjangorestframeworkAI26/6/202417/6/2026
Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags.
ModificadaCrítica (9.8)0.73%—Adobe Framemaker Publishing Server13/6/202417/6/2026
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker could exploit this vulnerability to gain access to sensitive information which may include system or user privileges. Exploitation…
ModificadaCrítica (9.8)1.1%—Adobe Framemaker Publishing Server13/6/202417/6/2026
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within the application. Exploitation of this issue…
ModificadaAlta (7)0.19%—Aveva PI Asset Framework Client12/6/202417/6/2026
There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.
ModificadaAlta (7.8)0.24%—Amazon AWS Deployment Framework11/6/202417/6/2026
The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined in AWS Organizations while taking…
ModificadaAlta (7.5)0.78%💥 PoCNinjaframework Ninja6/6/202417/6/2026
The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.
AnalizadaMedia (4.7)0.35%—Yiiframework YII30/5/202417/6/2026
Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a Cross-site Scripting (XSS) vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). This issue lies in the mechanism for displaying function…
AplazadaMedia (6.4)0.34%—Tinywebgallery Advanced IframeAI23/5/202417/6/2026
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_iframe_url_as_param_direct’ parameter in versions up to, and including, 2024.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AnalizadaAlta (7.5)0.46%—Luckyframeweb23/5/202417/6/2026
LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload method.
AplazadaMedia (5)0.40%—IframeAI23/5/202417/6/2026
The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to and including 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above…
AnalizadaMedia (6.5)0.33%—Swiftideas Swift Framework17/5/202417/6/2026
The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users…
AnalizadaAlta (7.8)0.18%—Intel Graphics Performance Analyzers Framework16/5/202417/6/2026
Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.8)0.21%—Intel Graphics Performance Analyzers Framework16/5/202417/6/2026
Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.8)0.20%—Intel Graphics Performance Analyzers Framework16/5/202417/6/2026
Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
Orbitaley — Vulnerabilidades