Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
1339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.41% | — | Pimcore Customer Management Framework | 10/5/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9. | |
| Modificada | Media (6.1) | 0.42% | — | Silverstripe Framework | 26/4/2023 | 17/6/2026 | Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an attacker can display a link to a third party website on a login screen by convincing a legitimate content author to follow a specially crafted link. Users should upgrade to… | |
| Modificada | Media (4.3) | 0.49% | — | Silverstripe Framework | 26/4/2023 | 17/6/2026 | Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access. Users… | |
| Modificada | Media (5.4) | 0.51% | — | Dradisframework Dradis | 25/4/2023 | 17/6/2026 | Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars. | |
| Analizada | Media (5.3) | 0.89% | — | Laravel Framework | 25/4/2023 | 17/6/2026 | The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not… | |
| Modificada | Media (6.5) | 0.74% | — | Slimframework Slim Psr-7 | 17/4/2023 | 17/6/2026 | slim/psr7 is a PSR-7 implementation for use with Slim 4. In versions prior to 1.6.1 an attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wild will also accept \n\n. An attacker that is… | |
| Modificada | Media (6.5) | 1.1% | — | Vmware Spring Framework | 13/4/2023 | 17/6/2026 | In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition. | |
| Modificada | Media (4.3) | 0.41% | — | SAP Application Interface Framework | 11/4/2023 | 17/6/2026 | The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confidentiality of the application. | |
| Modificada | Media (5.4) | 0.32% | — | SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core | 11/4/2023 | 17/6/2026 | The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images… | |
| Modificada | Media (4.6) | 0.32% | — | SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core | 11/4/2023 | 17/6/2026 | The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the… | |
| Modificada | Crítica (9.8) | 1.8% | — | Yiiframework YII | 4/4/2023 | 17/6/2026 | SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework. | |
| Modificada | Crítica (9.8) | 1.3% | — | Zend Framework | 4/4/2023 | 9/7/2026 | An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that surpasses 2.x.x and was deprecated in early 2020. | |
| Modificada | Alta (7.5) | 3.5% | 💥 PoC | Vmware Spring Framework | 27/3/2023 | 17/6/2026 | Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass. | |
| Modificada | Media (6.5) | 0.97% | — | Vmware Spring Framework | 23/3/2023 | 17/6/2026 | In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition. | |
| Modificada | Alta (7.8) | 0.30% | — | Adobe Framemaker | 17/2/2023 | 17/6/2026 | FrameMaker 2020 Update 4 (y anteriores) y 2022 (y anteriores), están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en una ejecución de código arbitrario en el contexto del usuario actual. Una explotación de este problema requiere la interacción del usuario, ya que la víctima debe… | |
| Modificada | Alta (7.8) | 0.33% | — | Adobe Framemaker | 17/2/2023 | 17/6/2026 | FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (5.5) | 0.33% | — | Adobe Framemaker | 17/2/2023 | 17/6/2026 | FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must… | |
| Modificada | Alta (7.8) | 0.30% | — | Adobe Framemaker | 17/2/2023 | 17/6/2026 | FrameMaker 2020 Update 4 (y anteriores) y 2022 (y anteriores), están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en una ejecución de código arbitrario en el contexto del usuario actual. Una explotación de este problema requiere la interacción del usuario, ya que la víctima debe… | |
| Modificada | Media (5.5) | 0.36% | — | Adobe Framemaker | 17/2/2023 | 17/6/2026 | FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open… | |
| Modificada | Crítica (9.8) | 0.34% | — | Vivo Frame Service | 17/2/2023 | 17/6/2026 | The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions. | |
| Modificada | Crítica (9.8) | 0.78% | — | Luckyframeweb | 17/2/2023 | 17/6/2026 | Se descubrió que LuckyframeWEB v3.5 contiene una vulnerabilidad de inyección SQL a través del parámetro dataScope en /system/DeptMapper.xml. | |
| Modificada | Crítica (9.8) | 0.78% | — | Luckyframeweb | 17/2/2023 | 17/6/2026 | Se descubrió que LuckyframeWEB v3.5 contiene una vulnerabilidad de inyección SQL a través del parámetro dataScope en /system/RoleMapper.xml. | |
| Modificada | Crítica (9.8) | 0.78% | — | Luckyframeweb | 17/2/2023 | 17/6/2026 | Se descubrió que LuckyframeWEB v3.5 contiene una vulnerabilidad de inyección SQL a través del parámetro dataScope en /system/UserMapper.xml. | |
| Modificada | Alta (7.8) | 1.1% | — | Microsoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022+1 | 14/2/2023 | 19/8/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Media (5) | 0.92% | — | Microsoft .net Framework | 14/2/2023 | 19/8/2026 | .NET Framework Denial of Service Vulnerability |