Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1099 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)8.0%—Apache ANTGradleFedoraproject FedoraOracle Agile Engineering Data Management+331/10/202017/6/2026
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still…
ModificadaMedia (6.1)1.3%—Encode Django Rest FrameworkRedhat Ceph StorageDebian Linux30/9/202017/6/2026
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious <script> tags, leading to a…
ModificadaMedia (6.5)11%💥 PoCVmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRMOracle Communications Design Studio+3419/9/202017/6/2026
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
ModificadaMedia (6.5)0.95%—HPE Universal API Framework18/9/202017/6/2026
A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework. The vulnerability could be remotely exploited to allow SQL injection in HPE Universal API Framework for VMware Esxi v2.5.2 and HPE Universal API Framework for Microsoft Hyper-V (VHD).
ModificadaAlta (8.1)7.3%💥 PoCFasterxml Jackson-databindOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Autovue FOR Agile Product Lifecycle Management+2217/9/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
ModificadaCrítica (10)78%💥 ExploitYiiframework YII15/9/202017/6/2026
Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38. A possible workaround without upgrading is available in the linked advisory.
ModificadaAlta (8.2)0.67%—Linuxfoundation THE Update Framework9/9/202017/6/2026
Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who is able to serve multiple new versions of root metadata (i.e. by a person-in-the-middle attack)…
ModificadaAlta (8.1)7.6%💥 PoCFasterxml Jackson-databindNetapp Active IQ Unified ManagerOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+2125/8/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
ModificadaMedia (6.5)0.53%—Lightbend Play Framework17/8/202017/6/2026
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
ModificadaMedia (5.5)1.1%—Microsoft .net Framework17/8/202017/6/2026
An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. To exploit this vulnerability, an attacker would need to send a specially crafted…
ModificadaAlta (7.8)3.8%—Microsoft .net Framework17/8/202017/6/2026
A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. To exploit the vulnerability, an attacker would need to be able to upload a specially crafted file to a web application. The…
ModificadaAlta (7.5)1.9%—Midasolutions Eframework24/7/202017/6/2026
There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authentication parameters.
ModificadaAlta (7.5)3.3%—Midasolutions Eframework24/7/202017/6/2026
Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
ModificadaCrítica (9.8)57%💥 ExploitMidasolutions Eframework24/7/202017/6/2026
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.
ModificadaCrítica (9.8)18%💥 ExploitMidasolutions Eframework24/7/202017/6/2026
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.
ModificadaCrítica (9.8)98%💥 ExploitMidasolutions Eframework24/7/202017/6/2026
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.
ModificadaMedia (6.1)0.94%—Midasolutions Eframework24/7/202017/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.
ModificadaMedia (5.4)0.56%—Midasolutions Eframework24/7/202017/6/2026
Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.
ModificadaMedia (5.4)0.69%—Jenkins Deployer Framework15/7/202017/6/2026
Jenkins Deployer Framework Plugin 1.2 and earlier does not escape the URL displayed in the build home page, resulting in a stored cross-site scripting vulnerability.
ModificadaAlta (7.6)0.93%—Oracle Applications Framework15/7/202017/6/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). The supported version that is affected is 12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.…
ModificadaBaja (2.7)0.97%—Oracle Applications Framework15/7/202017/6/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Page Request). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework.…
ModificadaAlta (8.2)1.4%—Oracle Applications Framework15/7/202017/6/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Popups). The supported version that is affected is 12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks…
ModificadaMedia (5.9)1.1%—Oracle Siebel UI Framework15/7/202017/6/2026
Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: SWSE Server). Supported versions that are affected are 20.6 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human…
AnalizadaAlta (7.8)94%⚠ Explotación activa💥 ExploitMicrosoft .net CoreMicrosoft .net FrameworkMicrosoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server+214/7/202017/6/2026
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
ModificadaAlta (7.5)87%💥 PoCApache TomcatDebian LinuxNetapp Oncommand System ManagerOpensuse Leap+1414/7/202025/8/2026
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
Orbitaley — Vulnerabilidades