Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.99% | — | Linuxfoundation THE Update Framework | 5/2/2020 | 17/6/2026 | TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature. | |
| Modificada | Alta (7.5) | 1.3% | — | Circl AIL Framework | 3/2/2020 | 17/6/2026 | Global.py in AIL framework 2.8 allows path traversal. | |
| Modificada | Media (6.1) | 1.0% | — | Zend Framework | 27/1/2020 | 17/6/2026 | CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email. | |
| Modificada | Alta (8.8) | 3.1% | 💥 Exploit | Adive Framework | 26/1/2020 | 17/6/2026 | Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password. | |
| Modificada | Media (6.1) | 0.87% | — | Adive Framework | 26/1/2020 | 17/6/2026 | Adive Framework 2.0.8 has admin/user/add userName XSS. | |
| Modificada | Media (6.1) | 0.87% | — | Adive Framework | 26/1/2020 | 17/6/2026 | Adive Framework 2.0.8 has admin/user/add userUsername XSS. | |
| Modificada | Media (6.1) | 0.80% | — | Cisco Data Center Analytics Framework | 26/1/2020 | 17/6/2026 | A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface of an affected system. The vulnerability is due to insufficient… | |
| Modificada | Media (5.3) | 2.4% | — | Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications BRM - Elastic Charging EngineOracle Communications Diameter Signaling Router+23 | 17/1/2020 | 17/6/2026 | Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and… | |
| Modificada | Alta (7.5) | 89% | 💥 PoC | Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Policy+29 | 17/1/2020 | 17/6/2026 | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input. | |
| Modificada | Media (5.3) | 1.3% | — | Oracle Applications Framework | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.2.5-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Applications… | |
| Modificada | Media (4.7) | 1.1% | — | Oracle Applications Framework | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle… | |
| Modificada | Media (5.3) | 1.6% | — | Oracle Siebel UI Framework | 15/1/2020 | 17/6/2026 | Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 19.10 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can… | |
| Modificada | Media (4.7) | 1.5% | — | Oracle Siebel UI Framework | 15/1/2020 | 17/6/2026 | Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: SWSE Server). Supported versions that are affected are 19.10 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human… | |
| Modificada | Media (5.3) | 1.7% | — | Oracle Siebel UI Framework | 15/1/2020 | 17/6/2026 | Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: UIF Open UI). Supported versions that are affected are 19.7 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Oracle Access ManagerOracle CoherenceOracle Commerce PlatformOracle Communications Diameter Signaling Router+5 | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle… | |
| Modificada | Alta (8.8) | 1.4% | — | Jenkins Robot Framework | 15/1/2020 | 17/6/2026 | Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Microsoft .net Framework | 14/1/2020 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'. | |
| Modificada | Alta (8.8) | 17% | — | Microsoft .net FrameworkMicrosoft .net Core | 14/1/2020 | 17/6/2026 | A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is… | |
| Modificada | Alta (8.8) | 18% | — | Microsoft .net FrameworkMicrosoft .net Core | 14/1/2020 | 17/6/2026 | A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is… | |
| Modificada | Media (5.3) | 1.8% | — | Linuxfoundation THE Update Framework | 14/1/2020 | 17/6/2026 | TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption. | |
| Modificada | Media (5.4) | 1.8% | — | Pivotal Software Spring Framework | 10/1/2020 | 17/6/2026 | The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or… | |
| Modificada | Media (6.1) | 1.0% | — | Koala-framework Koala Framework | 8/1/2020 | 16/6/2026 | Koala Framework before 2011-11-21 has XSS via the request_uri parameter. | |
| Modificada | Crítica (9.8) | 9.3% | 💥 Exploit | Bulbsecurity Smartphone Pentest Framework | 3/1/2020 | 16/6/2026 | Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl. | |
| Modificada | Alta (8.8) | 1.7% | — | Bulbsecurity Smartphone Pentest Framework | 3/1/2020 | 16/6/2026 | Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) remoteAttack.pl or (2) guessPassword.pl in frameworkgui/; the filename parameter to (3) CSAttack.pl or (4) SEAttack.pl in frameworkgui/; the… | |
| Modificada | Media (6.1) | 1.4% | — | Zend FrameworkFedoraproject FedoraRedhat Enterprise Linux | 3/1/2020 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7)… |