Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1099 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.99%—Linuxfoundation THE Update Framework5/2/202017/6/2026
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
ModificadaAlta (7.5)1.3%—Circl AIL Framework3/2/202017/6/2026
Global.py in AIL framework 2.8 allows path traversal.
ModificadaMedia (6.1)1.0%—Zend Framework27/1/202017/6/2026
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
ModificadaAlta (8.8)3.1%💥 ExploitAdive Framework26/1/202017/6/2026
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
ModificadaMedia (6.1)0.87%—Adive Framework26/1/202017/6/2026
Adive Framework 2.0.8 has admin/user/add userName XSS.
ModificadaMedia (6.1)0.87%—Adive Framework26/1/202017/6/2026
Adive Framework 2.0.8 has admin/user/add userUsername XSS.
ModificadaMedia (6.1)0.80%—Cisco Data Center Analytics Framework26/1/202017/6/2026
A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface of an affected system. The vulnerability is due to insufficient…
ModificadaMedia (5.3)2.4%—Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications BRM - Elastic Charging EngineOracle Communications Diameter Signaling Router+2317/1/202017/6/2026
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and…
ModificadaAlta (7.5)89%💥 PoCVmware Spring FrameworkOracle Application Testing SuiteOracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Policy+2917/1/202017/6/2026
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
ModificadaMedia (5.3)1.3%—Oracle Applications Framework15/1/202017/6/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.2.5-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Applications…
ModificadaMedia (4.7)1.1%—Oracle Applications Framework15/1/202017/6/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle…
ModificadaMedia (5.3)1.6%—Oracle Siebel UI Framework15/1/202017/6/2026
Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 19.10 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can…
ModificadaMedia (4.7)1.5%—Oracle Siebel UI Framework15/1/202017/6/2026
Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: SWSE Server). Supported versions that are affected are 19.10 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human…
ModificadaMedia (5.3)1.7%—Oracle Siebel UI Framework15/1/202017/6/2026
Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: UIF Open UI). Supported versions that are affected are 19.7 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this…
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitOracle Access ManagerOracle CoherenceOracle Commerce PlatformOracle Communications Diameter Signaling Router+515/1/202017/6/2026
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle…
ModificadaAlta (8.8)1.4%—Jenkins Robot Framework15/1/202017/6/2026
Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents.
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitMicrosoft .net Framework14/1/202017/6/2026
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
ModificadaAlta (8.8)17%—Microsoft .net FrameworkMicrosoft .net Core14/1/202017/6/2026
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is…
ModificadaAlta (8.8)18%—Microsoft .net FrameworkMicrosoft .net Core14/1/202017/6/2026
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is…
ModificadaMedia (5.3)1.8%—Linuxfoundation THE Update Framework14/1/202017/6/2026
TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.
ModificadaMedia (5.4)1.8%—Pivotal Software Spring Framework10/1/202017/6/2026
The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or…
ModificadaMedia (6.1)1.0%—Koala-framework Koala Framework8/1/202016/6/2026
Koala Framework before 2011-11-21 has XSS via the request_uri parameter.
ModificadaCrítica (9.8)9.3%💥 ExploitBulbsecurity Smartphone Pentest Framework3/1/202016/6/2026
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.
ModificadaAlta (8.8)1.7%—Bulbsecurity Smartphone Pentest Framework3/1/202016/6/2026
Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) remoteAttack.pl or (2) guessPassword.pl in frameworkgui/; the filename parameter to (3) CSAttack.pl or (4) SEAttack.pl in frameworkgui/; the…
ModificadaMedia (6.1)1.4%—Zend FrameworkFedoraproject FedoraRedhat Enterprise Linux3/1/202016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7)…
Orbitaley — Vulnerabilidades