Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1099 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.81%—Sumocoders Frameworkuserbundle3/1/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in sumocoders FrameworkUserBundle up to 1.3.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the file Resources/views/Security/login.html.twig. The manipulation leads to information exposure through error message.…
ModificadaCrítica (9.8)0.82%—Centralized Salesforce Development Framework Project Centralized Salesforce Development Framework2/1/202317/6/2026
A vulnerability was found in Centralized-Salesforce-Dev-Framework. It has been declared as problematic. Affected by this vulnerability is the function SObjectService of the file src/classes/SObjectService.cls of the component SOQL Handler. The manipulation of the argument orderDirection leads to injection. The patch…
ModificadaAlta (7.5)1.2%—Aahframework AAH27/12/202217/6/2026
Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.
ModificadaMedia (6.1)0.59%—Hitachi Community Plugin Framework21/12/202217/6/2026
A vulnerability classified as problematic has been found in Webdetails cpf up to 9.5.0.0-80. Affected is an unknown function of the file core/src/main/java/pt/webdetails/cpf/packager/DependenciesPackage.java. The manipulation of the argument baseUrl leads to cross site scripting. It is possible to launch the attack…
ModificadaAlta (7.8)1.2%—Microsoft .net Framework13/12/202217/6/2026
.NET Framework Remote Code Execution Vulnerability
ModificadaMedia (6.1)0.46%—Nuxt Framework12/12/202217/6/2026
Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13.
ModificadaMedia (6.1)0.52%—Nuxt Framework12/12/202217/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository nuxt/framework prior to v3.0.0-rc.13.
ModificadaMedia (5.4)0.61%—Yiiframework GII9/12/202217/6/2026
Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.
ModificadaAlta (7.8)0.42%—Nttdata Terasoluna Global FrameworkNttdata Terasoluna Server Framework FOR Java (rich)5/12/202217/6/2026
TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0.5.1 are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spring Framework which contains the vulnerability.The vulnerability is caused by an improper input…
ModificadaCrítica (9.8)1.2%—Yiiframework YII23/11/202217/6/2026
`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.
ModificadaMedia (5.4)0.55%—Silverstripe Framework23/11/202217/6/2026
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).
ModificadaMedia (5.4)0.63%—Silverstripe Framework23/11/202217/6/2026
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.
ModificadaMedia (5.4)0.55%—Silverstripe Framework23/11/202217/6/2026
Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).
ModificadaMedia (5.4)0.51%—Silverstripe Framework23/11/202217/6/2026
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.
ModificadaMedia (5.4)0.68%—Silverstripe Asset AdminSilverstripe AssetsSilverstripe Framework23/11/202217/6/2026
Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS.
ModificadaMedia (6.1)0.50%—Silverstripe Framework22/11/202217/6/2026
Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.
ModificadaAlta (8.8)0.77%—Silverstripe Framework21/11/202217/6/2026
Silverstripe silverstripe/framework through 4.11 allows SQL Injection.
ModificadaMedia (5.4)0.56%—Silverstripe Framework21/11/202217/6/2026
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3).
ModificadaMedia (5.8)0.80%—Microsoft .net FrameworkMicrosoft Nuget9/11/202210/8/2026
.NET Framework Information Disclosure Vulnerability
ModificadaMedia (6.5)0.75%—Oracle Applications Framework18/10/202217/6/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Session Management). Supported versions that are affected are 12.2.6-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.…
ModificadaAlta (7.5)1.3%—Opensecurity Mobile Security Framework18/10/202217/6/2026
Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files via a crafted HTTP request.
ModificadaAlta (7.5)0.57%—Phoenixframework Phoenix17/10/202217/6/2026
socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token.
ModificadaAlta (7.8)1.6%—Microsoft .net Framework13/9/202217/6/2026
.NET Framework Remote Code Execution Vulnerability
AnalizadaAlta (7.5)95%⚠ Explotación activa💥 ExploitZkoss ZK Framework26/8/202217/6/2026
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.
ModificadaMedia (4.3)0.56%—Jenkins Deployer Framework27/7/202217/6/2026
A missing permission check in Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier allows attackers with Item/Read permission but without Deploy Now/Deploy permission to read deployment logs.
Orbitaley — Vulnerabilidades