Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.81% | — | Sumocoders Frameworkuserbundle | 3/1/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in sumocoders FrameworkUserBundle up to 1.3.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the file Resources/views/Security/login.html.twig. The manipulation leads to information exposure through error message.… | |
| Modificada | Crítica (9.8) | 0.82% | — | Centralized Salesforce Development Framework Project Centralized Salesforce Development Framework | 2/1/2023 | 17/6/2026 | A vulnerability was found in Centralized-Salesforce-Dev-Framework. It has been declared as problematic. Affected by this vulnerability is the function SObjectService of the file src/classes/SObjectService.cls of the component SOQL Handler. The manipulation of the argument orderDirection leads to injection. The patch… | |
| Modificada | Alta (7.5) | 1.2% | — | Aahframework AAH | 27/12/2022 | 17/6/2026 | Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read. | |
| Modificada | Media (6.1) | 0.59% | — | Hitachi Community Plugin Framework | 21/12/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in Webdetails cpf up to 9.5.0.0-80. Affected is an unknown function of the file core/src/main/java/pt/webdetails/cpf/packager/DependenciesPackage.java. The manipulation of the argument baseUrl leads to cross site scripting. It is possible to launch the attack… | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft .net Framework | 13/12/2022 | 17/6/2026 | .NET Framework Remote Code Execution Vulnerability | |
| Modificada | Media (6.1) | 0.46% | — | Nuxt Framework | 12/12/2022 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13. | |
| Modificada | Media (6.1) | 0.52% | — | Nuxt Framework | 12/12/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository nuxt/framework prior to v3.0.0-rc.13. | |
| Modificada | Media (5.4) | 0.61% | — | Yiiframework GII | 9/12/2022 | 17/6/2026 | Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field. | |
| Modificada | Alta (7.8) | 0.42% | — | Nttdata Terasoluna Global FrameworkNttdata Terasoluna Server Framework FOR Java (rich) | 5/12/2022 | 17/6/2026 | TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0.5.1 are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spring Framework which contains the vulnerability.The vulnerability is caused by an improper input… | |
| Modificada | Crítica (9.8) | 1.2% | — | Yiiframework YII | 23/11/2022 | 17/6/2026 | `yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27. | |
| Modificada | Media (5.4) | 0.55% | — | Silverstripe Framework | 23/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3). | |
| Modificada | Media (5.4) | 0.63% | — | Silverstripe Framework | 23/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view. | |
| Modificada | Media (5.4) | 0.55% | — | Silverstripe Framework | 23/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2). | |
| Modificada | Media (5.4) | 0.51% | — | Silverstripe Framework | 23/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters. | |
| Modificada | Media (5.4) | 0.68% | — | Silverstripe Asset AdminSilverstripe AssetsSilverstripe Framework | 23/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS. | |
| Modificada | Media (6.1) | 0.50% | — | Silverstripe Framework | 22/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request. | |
| Modificada | Alta (8.8) | 0.77% | — | Silverstripe Framework | 21/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 allows SQL Injection. | |
| Modificada | Media (5.4) | 0.56% | — | Silverstripe Framework | 21/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3). | |
| Modificada | Media (5.8) | 0.80% | — | Microsoft .net FrameworkMicrosoft Nuget | 9/11/2022 | 10/8/2026 | .NET Framework Information Disclosure Vulnerability | |
| Modificada | Media (6.5) | 0.75% | — | Oracle Applications Framework | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Session Management). Supported versions that are affected are 12.2.6-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Modificada | Alta (7.5) | 1.3% | — | Opensecurity Mobile Security Framework | 18/10/2022 | 17/6/2026 | Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files via a crafted HTTP request. | |
| Modificada | Alta (7.5) | 0.57% | — | Phoenixframework Phoenix | 17/10/2022 | 17/6/2026 | socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token. | |
| Modificada | Alta (7.8) | 1.6% | — | Microsoft .net Framework | 13/9/2022 | 17/6/2026 | .NET Framework Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 95% | ⚠ Explotación activa💥 Exploit | Zkoss ZK Framework | 26/8/2022 | 17/6/2026 | ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader. | |
| Modificada | Media (4.3) | 0.56% | — | Jenkins Deployer Framework | 27/7/2022 | 17/6/2026 | A missing permission check in Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier allows attackers with Item/Read permission but without Deploy Now/Deploy permission to read deployment logs. |