Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.5% | — | Laravel Framework | 20/12/2021 | 17/6/2026 | OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17. | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modificada | Media (6.6) | 4.4% | — | QOS LogbackRedhat SatelliteNetapp Cloud ManagerNetapp Service Level Manager+2 | 16/12/2021 | 17/6/2026 | In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers. | |
| Modificada | Crítica (9.8) | 2.8% | — | Microsoft BOT Framework Software Development KIT | 15/12/2021 | 17/6/2026 | Bot Framework SDK Remote Code Execution Vulnerability | |
| Modificada | Alta (7.7) | 1.0% | — | SAP Saf-t Framework | 14/12/2021 | 17/6/2026 | SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to full server directory access. The attacker can see the whole filesystem structure but cannot overwrite, delete, or corrupt arbitrary files on the server. | |
| Modificada | Media (6.1) | 0.83% | — | Laravel Framework | 8/12/2021 | 17/6/2026 | Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating engine. A broken HTML element may be clicked and the user taken to another location in their browser due to XSS. This is due to the user… | |
| Modificada | Crítica (9.8) | 1.4% | — | Swoole PHP Framework | 3/12/2021 | 17/6/2026 | matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php. | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Laravel Framework | 14/11/2021 | 17/6/2026 | Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is… | |
| Modificada | Media (4.3) | 1.4% | — | Vmware Spring FrameworkNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Metrocluster Tiebreaker+4 | 28/10/2021 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. | |
| Modificada | Media (5.4) | 0.57% | — | Macrob7 Macs Framework Content Management System Project Macrob7 Macs Framework Content Management System | 22/10/2021 | 17/6/2026 | Macrob7 Macs Framework Content Management System - 1.14f contains a cross-site scripting (XSS) vulnerability in the account reset function, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the e-mail input field. | |
| Modificada | Media (5.3) | 1.5% | — | Oracle Applications Framework | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Session Management). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications… | |
| Modificada | Alta (8.7) | 1.5% | — | Linuxfoundation THE Update Framework | 19/10/2021 | 17/6/2026 | python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and `tuf/ngclient`), there is a path traversal vulnerability that in the worst case can overwrite files ending in `.json` anywhere on the client system on a call to `get_one_valid_targetinfo()`. It occurs… | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Gambit Titan Framework | 6/9/2021 | 17/6/2026 | The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (5.3) | 29% | 💥 Exploit | Gutenberg Template Library & Redux Framework | 2/9/2021 | 17/6/2026 | The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash… | |
| Modificada | Media (6.5) | 1.3% | — | Gutenberg Template Library & Redux Framework | 2/9/2021 | 17/6/2026 | The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”. The `permissions_callback` used in this file only checked for the… | |
| Analizada | Alta (8.5) | 98% | ⚠ Explotación activa💥 Exploit | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 11% | 💥 Exploit | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 7/10/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected,… | |
| Analizada | Alta (8.5) | 3.4% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 7/10/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected,… | |
| Analizada | Media (6.3) | 5.9% | — | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+11 | 23/8/2021 | 7/10/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 7/10/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.5% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+9 | 23/8/2021 | 7/10/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 7/10/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 7/10/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 7/10/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 7/10/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… |