Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.46% | — | Vmware Spring Framework | 27/8/2026 | 10/9/2026 | A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE | |
| Analizada | Media (6.1) | 0.24% | — | Vmware Spring Framework | 27/8/2026 | 10/9/2026 | A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0… | |
| Analizada | Alta (7.5) | 0.46% | — | Vmware Spring Framework | 27/8/2026 | 10/9/2026 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring… | |
| En análisis | Alta (7.5) | 0.37% | — | Vmware Spring Framework | 27/8/2026 | 10/9/2026 | The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 | |
| Analizada | Crítica (9.8) | 0.60% | 💥 PoC | Vmware Spring Framework | 27/8/2026 | 10/9/2026 | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework… | |
| Analizada | Media (6.1) | 0.26% | 💥 PoC | Vmware Spring Framework | 27/8/2026 | 10/9/2026 | UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 | |
| Pendiente de análisis | Media (5.1) | 0.16% | — | Rapid7 Metasploit FrameworkAI | 27/8/2026 | 28/8/2026 | A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set, the application resets the internal state… | |
| Aplazada | Media (5.5) | 0.71% | — | Cleverbrush FrameworkAI | 25/8/2026 | 28/9/2026 | A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Alta (7.1) | 0.40% | — | Circl AIL FrameworkAI | 19/8/2026 | 26/8/2026 | AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can submit an arbitrary URL for crawling without adequate validation of the destination host. The crawler can therefore be… | |
| Analizada | Alta (7.4) | 0.16% | — | Oracle Autonomous Health Framework | 18/8/2026 | 26/8/2026 | Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework… | |
| Analizada | Alta (8.4) | 0.14% | — | Oracle Autonomous Health Framework | 18/8/2026 | 26/8/2026 | Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes… | |
| Analizada | Alta (8.5) | 0.30% | — | Oracle Autonomous Health Framework | 18/8/2026 | 26/8/2026 | Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Autonomous Health Framework.… | |
| Analizada | Media (6.7) | 0.24% | — | Oracle Autonomous Health Framework | 18/8/2026 | 26/8/2026 | Vulnerability in Oracle Autonomous Health Framework (component: Cluster Health Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware… | |
| Analizada | Media (6.8) | 0.42% | — | Oracle Autonomous Health Framework | 18/8/2026 | 26/8/2026 | Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where… | |
| Aplazada | Alta (8.8) | 0.94% | 💥 PoC | HaloAISpringframeworkAI | 18/8/2026 | 31/8/2026 | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components | |
| Aplazada | Baja (2.9) | 0.59% | — | Treefrogframework Treefrog-frameworkAI | 17/8/2026 | 20/8/2026 | A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.2. This vulnerability affects the function std::strncmp of the file src/tsessioncookiestore.cpp of the component Session Cookie Handler. The manipulation results in improper authentication. The attack can be launched remotely. A… | |
| Aplazada | Media (5.6) | 0.39% | — | Quasar FrameworkAI | 13/8/2026 | 9/9/2026 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without rejecting an own __proto__ property. The merge… | |
| Analizada | Alta (7.5) | 0.61% | — | Ash-hq ASH Framework | 12/8/2026 | 18/8/2026 | Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the data layer. Read actions with keyset pagination decode the client-supplied… | |
| Pendiente de análisis | Media (4.3) | 0.37% | — | Django Rest FrameworkAI | 11/8/2026 | 11/9/2026 | Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.get() without view.check_permissions() while rendering an invalid write request,… | |
| Pendiente de análisis | Media (5.3) | 0.56% | — | Django-rest-framework Django Rest FrameworkAI | 11/8/2026 | 11/9/2026 | Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing… | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net | 11/8/2026 | 17/8/2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.40% | — | Microsoft .net Framework | 11/8/2026 | 14/8/2026 | Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (7) | 0.37% | — | Microsoft .net FrameworkMicrosoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft .net Framework | 11/8/2026 | 14/8/2026 | Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.4) | 0.16% | — | Intel Approximate Bayesian Inference Framework | 11/8/2026 | 2/10/2026 | Uncontrolled search path for some Approximate Bayesian Inference Framework before version on commit #484c949 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This… |