Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

1098 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.60%—Vmware Spring Framework27/8/202610/9/2026
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework…
AnalizadaMedia (6.1)0.26%—Vmware Spring Framework27/8/202610/9/2026
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Pendiente de análisisMedia (5.1)0.16%—Rapid7 Metasploit FrameworkAI27/8/202628/8/2026
A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set, the application resets the internal state…
AplazadaMedia (5.5)0.71%—Cleverbrush FrameworkAI25/8/202628/9/2026
A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been…
AplazadaAlta (7.1)0.40%—Circl AIL FrameworkAI19/8/202626/8/2026
AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can submit an arbitrary URL for crawling without adequate validation of the destination host. The crawler can therefore be…
AnalizadaAlta (7.4)0.16%—Oracle Autonomous Health Framework18/8/202626/8/2026
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework…
AnalizadaAlta (8.4)0.14%—Oracle Autonomous Health Framework18/8/202626/8/2026
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes…
AnalizadaAlta (8.5)0.30%—Oracle Autonomous Health Framework18/8/202626/8/2026
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Autonomous Health Framework.…
AnalizadaMedia (6.7)0.24%—Oracle Autonomous Health Framework18/8/202626/8/2026
Vulnerability in Oracle Autonomous Health Framework (component: Cluster Health Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware…
AnalizadaMedia (6.8)0.42%—Oracle Autonomous Health Framework18/8/202626/8/2026
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where…
AplazadaAlta (8.8)0.94%—HaloAISpringframeworkAI18/8/202631/8/2026
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components
AplazadaBaja (2.9)0.59%—Treefrogframework Treefrog-frameworkAI17/8/202620/8/2026
A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.2. This vulnerability affects the function std::strncmp of the file src/tsessioncookiestore.cpp of the component Session Cookie Handler. The manipulation results in improper authentication. The attack can be launched remotely. A…
AplazadaMedia (5.6)0.39%—Quasar FrameworkAI13/8/20269/9/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without rejecting an own __proto__ property. The merge…
AnalizadaAlta (7.5)0.61%—Ash-hq ASH Framework12/8/202618/8/2026
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the data layer. Read actions with keyset pagination decode the client-supplied…
Pendiente de análisisMedia (4.3)0.37%—Django Rest FrameworkAI11/8/202611/9/2026
Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.get() without view.check_permissions() while rendering an invalid write request,…
Pendiente de análisisMedia (5.3)0.56%—Django-rest-framework Django Rest FrameworkAI11/8/202611/9/2026
Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing…
AnalizadaAlta (7.8)0.36%—Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net11/8/202617/8/2026
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.40%—Microsoft .net Framework11/8/202614/8/2026
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.37%—Microsoft .net FrameworkMicrosoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net11/8/202614/8/2026
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)0.78%—Microsoft .net Framework11/8/202614/8/2026
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.4)0.16%—Intel Approximate Bayesian Inference Framework11/8/20262/10/2026
Uncontrolled search path for some Approximate Bayesian Inference Framework before version on commit #484c949 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This…
AnalizadaMedia (5.4)0.12%—Intel Workload Sevices Framework11/8/20262/10/2026
Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur…
Pendiente de análisisMedia (5.3)0.29%—Axis Signed Video FrameworkAI11/8/20263/9/2026
The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signed content. The AXIS OS device's signed video functionality remains unaffected.
Pendiente de análisisBaja (2.1)0.60%—Phoenixframework Phoenix Live ViewAI10/8/202612/8/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attacker to send a victim's browser to an origin of the attacker's choosing via a :to value containing ASCII tab, LF or CR. redirect/2 validates :to through the private validate_local_url!/2 in…
AplazadaAlta (8.8)0.26%—Freepbx FrameworkAI10/8/202628/8/2026
A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator.