Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
1339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+1 | 12/9/2023 | 17/6/2026 | Vulnerabilidad de Ejecución Remota de Códigode Visual Studio | |
| Modificada | Alta (7.8) | 1.0% | — | Microsoft .net Framework | 12/9/2023 | 17/6/2026 | Vulnerabilidad de Ejecución Remota de Código de .NET Framework | |
| Modificada | Crítica (9.8) | 1.4% | — | Weblogic-framework Project Weblogic-framework | 25/8/2023 | 17/6/2026 | weblogic-framework es una herramienta para detectar vulnerabilidades de weblogic. Las versiones 0.2.3 y anteriores no verifican los paquetes de datos devueltos, y existe una vulnerabilidad de deserialización que puede conducir a la ejecución remota de código. Cuando weblogic-framework recibe el comando echo,… | |
| Modificada | Media (4.8) | 0.37% | — | Iframe Project Iframe | 25/8/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) Almacenada en el plugin iframe popup de Gopi Ramasamy que afecta a las versiones 3.3 e inferiores. Para explotar esta vulnerabilidad hace falta estar autenticado y tener permisos de administrador o superior. | |
| Modificada | Alta (8.8) | 77% | 💥 PoC | Microsoft .net Framework | 8/8/2023 | 10/8/2026 | ASP.NET Elevation of Privilege Vulnerability | |
| Modificada | Media (5.9) | 1.5% | — | Microsoft .net Framework | 8/8/2023 | 10/8/2026 | .NET Framework Spoofing Vulnerability | |
| Analizada | Media (5.4) | 0.61% | — | Pimcore Customer Management Framework | 3/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2. | |
| Modificada | Media (6.1) | 0.40% | — | Yiiframework YII | 28/7/2023 | 17/6/2026 | Se ha descubierto que Yii 2 v2.0.45 contiene una vulnerabilidad Cross-Site Scripting (XSS) a través del endpoint "/books". | |
| Modificada | Media (6.1) | 0.42% | — | Oracle Applications Framework | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.3-12.3.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Modificada | Media (6.5) | 0.54% | — | Pimcore Customer Management Framework | 10/7/2023 | 17/6/2026 | Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1. | |
| Modificada | Media (5.4) | 0.54% | — | Simple Iframe Project Simple Iframe | 10/7/2023 | 17/6/2026 | The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.36% | — | Iframe Shortcode Project Iframe Shortcode | 26/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Flyn San IFrame Shortcode plugin <= 1.0.5 versions. | |
| Modificada | Alta (7.5) | 2.2% | — | Microsoft .net Framework | 14/6/2023 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 2.6% | — | Microsoft .net FrameworkMicrosoft .net | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.8) | 0.90% | — | Microsoft .net Framework | 14/6/2023 | 17/6/2026 | .NET Framework Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 1.6% | — | Microsoft .net FrameworkMicrosoft .net | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual StudioMicrosoft Visual Studio 2017+2 | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.1% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Media (6.1) | 0.46% | — | Woocommerce Wooframework Tweaks | 5/6/2023 | 17/6/2026 | A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by this vulnerability is the function admin_screen_logic of the file wooframework-tweaks.php. The manipulation of the argument url leads to open redirect. The attack can be launched remotely. Upgrading… | |
| Modificada | Media (6.1) | 0.66% | — | Woocommerce Wooframework Branding | 5/6/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_screen_logic of the file wooframework-branding.php. The manipulation of the argument url leads to open redirect. It is possible to launch the attack remotely. Upgrading to… | |
| Analizada | Media (4.9) | 0.55% | — | Pimcore Customer Management Framework | 25/5/2023 | 17/6/2026 | Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10. | |
| Modificada | Alta (8.8) | 0.32% | — | Kopatheme Kopa Framework | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kopa Theme Kopa Framework plugin <= 1.3.5 versions. | |
| Modificada | Alta (7.2) | 0.94% | — | Pimcore Customer Management Framework | 17/5/2023 | 17/6/2026 | SQL Injection in GitHub repository pimcore/customer-data-framework prior to 3.3.10. | |
| Modificada | Alta (7.8) | 0.14% | — | Intel Oneapi AI Analytics ToolkitIntel Oneapi Base ToolkitIntel Oneapi DL Framework Developer ToolkitIntel Oneapi HPC Toolkit+2 | 12/5/2023 | 17/6/2026 | Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.3) | 0.76% | — | Pimcore Customer Management Framework | 11/5/2023 | 17/6/2026 | The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the `Conditions` tab since the counter can be a negative number. This vulnerability is capable of the… |