Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1099 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.66%—Woocommerce Wooframework Branding5/6/202317/6/2026
A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_screen_logic of the file wooframework-branding.php. The manipulation of the argument url leads to open redirect. It is possible to launch the attack remotely. Upgrading to…
AnalizadaMedia (4.9)0.55%—Pimcore Customer Management Framework25/5/202317/6/2026
Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10.
ModificadaAlta (8.8)0.32%—Kopatheme Kopa Framework24/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kopa Theme Kopa Framework plugin <= 1.3.5 versions.
ModificadaAlta (7.2)0.94%—Pimcore Customer Management Framework17/5/202317/6/2026
SQL Injection in GitHub repository pimcore/customer-data-framework prior to 3.3.10.
ModificadaAlta (7.8)0.14%—Intel Oneapi AI Analytics ToolkitIntel Oneapi Base ToolkitIntel Oneapi DL Framework Developer ToolkitIntel Oneapi HPC Toolkit+212/5/202317/6/2026
Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.3)0.76%—Pimcore Customer Management Framework11/5/202317/6/2026
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the `Conditions` tab since the counter can be a negative number. This vulnerability is capable of the…
ModificadaAlta (7.8)0.41%—Pimcore Customer Management Framework10/5/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9.
ModificadaMedia (6.1)0.42%—Silverstripe Framework26/4/202317/6/2026
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an attacker can display a link to a third party website on a login screen by convincing a legitimate content author to follow a specially crafted link. Users should upgrade to…
ModificadaMedia (4.3)0.49%—Silverstripe Framework26/4/202317/6/2026
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access. Users…
ModificadaMedia (5.4)0.51%—Dradisframework Dradis25/4/202317/6/2026
Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.
AnalizadaMedia (5.3)0.89%—Laravel Framework25/4/202317/6/2026
The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not…
ModificadaMedia (6.5)0.74%—Slimframework Slim Psr-717/4/202317/6/2026
slim/psr7 is a PSR-7 implementation for use with Slim 4. In versions prior to 1.6.1 an attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wild will also accept \n\n. An attacker that is…
ModificadaMedia (6.5)1.1%—Vmware Spring Framework13/4/202317/6/2026
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
ModificadaMedia (4.3)0.41%—SAP Application Interface Framework11/4/202317/6/2026
The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confidentiality of the application.
ModificadaMedia (5.4)0.32%—SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core11/4/202317/6/2026
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images…
ModificadaMedia (4.6)0.32%—SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core11/4/202317/6/2026
The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the…
ModificadaCrítica (9.8)1.8%—Yiiframework YII4/4/202317/6/2026
SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.
ModificadaCrítica (9.8)1.3%—Zend Framework4/4/20239/7/2026
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that surpasses 2.x.x and was deprecated in early 2020.
ModificadaAlta (7.5)3.5%💥 PoCVmware Spring Framework27/3/202317/6/2026
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
ModificadaMedia (6.5)0.97%—Vmware Spring Framework23/3/202317/6/2026
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
ModificadaAlta (7.8)1.1%—Microsoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022+114/2/202319/8/2026
.NET and Visual Studio Remote Code Execution Vulnerability
ModificadaMedia (5)0.92%—Microsoft .net Framework14/2/202319/8/2026
.NET Framework Denial of Service Vulnerability
ModificadaAlta (8.8)1.5%—Yiiframework GII21/1/202317/6/2026
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.
ModificadaAlta (7.3)0.21%—Oracle Global Lifecycle Management Nextgen OUI Framework18/1/202317/6/2026
Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issues). Supported versions that are affected are Prior to 13.9.4.2.11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…
ModificadaMedia (6.1)0.41%—Phoenixframework Phoenix Html10/1/202317/6/2026
tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.