Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer. | |
| Aplazada | Media (5.1) | 0.45% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function. | |
| Aplazada | Media (4.6) | 0.53% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component. | |
| Aplazada | Alta (8.3) | 0.44% | — | Circl AIL FrameworkAI | 22/6/2026 | 22/6/2026 | A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cause file paths to resolve outside the intended image, favicon, or screenshot… | |
| Aplazada | Media (5.3) | 0.51% | — | Circl AIL FrameworkAI | 19/6/2026 | 22/6/2026 | AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2 query parameters and, prior to the fix, attempted to retrieve and compare item contents without first verifying that both referenced items existed as valid AIL objects.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.9) | 0.39% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.6) | 0.36% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Alta (8.1) | 0.38% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.9) | 0.39% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Media (4.7) | 0.14% | — | Oracle Application Development Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle… | |
| Analizada | Media (4.1) | 0.14% | — | Oracle Application Development Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Application Development Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… |