Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 3.0% | 💥 Exploit | Adobe Coldfusion | 30/6/2026 | 28/8/2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories… | |
| Analizada | Alta (8.8) | 0.55% | — | Adobe Coldfusion | 30/6/2026 | 28/8/2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this… | |
| Analizada | Alta (8.6) | 0.83% | — | Adobe Coldfusion | 30/6/2026 | 28/8/2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require… | |
| Analizada | Crítica (10) | 1.3% | — | Adobe Coldfusion | 30/6/2026 | 28/8/2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (10) | 42% | ⚠ Explotación activa💥 Exploit | Adobe Coldfusion | 30/6/2026 | 28/8/2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (10) | 1.4% | — | Adobe Coldfusion | 30/6/2026 | 28/8/2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (10) | 1.3% | — | Adobe Coldfusion | 30/6/2026 | 28/8/2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (10) | 1.3% | — | Adobe Coldfusion | 30/6/2026 | 28/8/2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Aplazada | Media (6.4) | 0.33% | — | Surbma Infusionsoft ShortcodeAI | 27/6/2026 | 29/6/2026 | The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusionsoft-form' shortcode in versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied 'account' and 'id' shortcode attributes in the… | |
| Aplazada | Alta (8.8) | 0.42% | — | Fusion BuilderAI | 26/6/2026 | 29/6/2026 | Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions. | |
| Analizada | Crítica (9.6) | 0.70% | — | Autodesk Fusion | 22/6/2026 | 24/6/2026 | A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user. | |
| Aplazada | Alta (7.7) | 0.47% | — | Avada Fusion BuilderAI | 17/6/2026 | 17/6/2026 | Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Fusion BuilderAI | 17/6/2026 | 17/6/2026 | Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions. | |
| Analizada | Alta (7.8) | 0.20% | — | Leejet Stable-diffusion.cpp | 16/6/2026 | 25/6/2026 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the GLOBAL opcode handler. The issue was… | |
| Analizada | Alta (7.8) | 0.20% | — | Leejet Stable-diffusion.cpp | 16/6/2026 | 25/6/2026 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the BINUNICODE opcode handler. The issue… | |
| Analizada | Alta (7.8) | 0.21% | — | Leejet Stable-diffusion.cpp | 16/6/2026 | 25/6/2026 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to heap buffer overflow in SHORT_BINUNICODE parsing for PyTorch checkpoint files. The pickle .ckpt parser in src/model.cpp… | |
| Analizada | Media (5.5) | 0.16% | — | Leejet Stable-diffusion.cpp | 16/6/2026 | 25/6/2026 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to an out-of-bounds reads error through PyTorch checkpoint pickle opcode parsing. The pickle .ckpt parser in src/model.cpp… | |
| Aplazada | Crítica (9.8) | 0.56% | 💥 PoC | Keap Infusionsoft IntegrationAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions. | |
| Analizada | Alta (7.4) | 0.84% | — | Adobe Coldfusion | 9/6/2026 | 28/8/2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope.… | |
| Analizada | Media (4.8) | 0.36% | — | Adobe Coldfusion | 9/6/2026 | 28/8/2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing… | |
| Analizada | Alta (8.8) | 0.51% | — | Adobe Coldfusion | 9/6/2026 | 28/8/2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The… | |
| Analizada | Alta (8.4) | 0.47% | — | Adobe Coldfusion | 9/6/2026 | 28/8/2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. The vulnerable component is… | |
| Analizada | Alta (8.1) | 0.87% | — | Adobe Coldfusion | 9/6/2026 | 28/8/2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does… | |
| Analizada | Alta (8.4) | 0.45% | — | Adobe Coldfusion | 9/6/2026 | 28/8/2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session.… | |
| Analizada | Crítica (9.6) | 0.49% | — | Adobe Coldfusion | 9/6/2026 | 28/8/2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require… |