Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.21% | — | Vmware WorkstationAIVmware FusionAI | 26/2/2026 | 17/6/2026 | VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of other Guest VM's. Resolution: To remediate CVE-2026-22715 please upgrade to VMware… | |
| Aplazada | Media (6.5) | 0.23% | — | Themefusion Fusion BuilderAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder fusion-builder allows Stored XSS.This issue affects Fusion Builder: from n/a through <= 3.14.1. | |
| Analizada | Alta (7.9) | 1.3% | 💥 Exploit | Rocketsoftware Trufusion Enterprise | 17/2/2026 | 17/6/2026 | Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource. | |
| Analizada | Crítica (9.4) | 1.1% | — | Rocketsoftware Trufusion Enterprise | 17/2/2026 | 17/6/2026 | Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to be included. This allows writing files to… | |
| Analizada | Media (5.1) | 0.28% | — | Php-fusion Phpfusion | 5/2/2026 | 17/6/2026 | PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by submitting crafted input to the… | |
| Analizada | Alta (8.6) | 0.63% | — | Php-fusion Phpfusion | 5/2/2026 | 17/6/2026 | PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content POST parameters to the panels.php… | |
| Aplazada | Media (5.1) | 0.26% | — | Php-fusion PhpfusionAI | 30/1/2026 | 17/6/2026 | PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly sanitize user-submitted message content. Attackers can inject malicious JavaScript through forum messages that will execute when the print page is generated, allowing script execution in victim… | |
| Modificada | Alta (8.1) | 0.67% | — | Autodesk Fusion | 22/1/2026 | 17/6/2026 | A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the… | |
| Modificada | Alta (8.1) | 0.55% | — | Autodesk Fusion | 22/1/2026 | 17/6/2026 | A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current… | |
| Modificada | Alta (8.1) | 0.69% | — | Autodesk Fusion | 22/1/2026 | 17/6/2026 | A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute… | |
| Analizada | Media (5.1) | 0.26% | — | Php-fusion Phpfusion | 17/12/2025 | 17/6/2026 | PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload SVG files with script tags that execute arbitrary JavaScript when viewed, potentially stealing user session information or… | |
| Modificada | Media (5.3) | 0.25% | — | Theme-fusion Avada | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in ThemeFusion Avada avada allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Avada: from n/a through <= 7.13.2. | |
| Analizada | Media (6.9) | 0.40% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguish between existing and non-existing accounts by analyzing the server's error… | |
| Analizada | Alta (8.7) | 0.42% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system information. | |
| Analizada | Media (6.9) | 0.27% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new admin user with full system privileges… | |
| Analizada | Alta (8.8) | 0.90% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backup and deletion operations through unverified input parameters. Attackers can exploit path traversal techniques in index.php to write backup files to arbitrary locations… | |
| Aplazada | Alta (8.7) | 0.44% | — | Google Cloud Data FusionAICdapio CdapAI | 10/12/2025 | 25/9/2026 | A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifacts to a Data Fusion instance can execute arbitrary code within the core AppFabric component. This could allow the attacker to gain control over the Data Fusion instance, potentially leading to… | |
| Analizada | Media (5.3) | 0.44% | — | Adobe Coldfusion | 9/12/2025 | 25/9/2026 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting improperly stored or transmitted credentials.… | |
| Analizada | Media (5.6) | 0.13% | — | Adobe Coldfusion | 9/12/2025 | 25/9/2026 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access potentially resulting in denial of service. Exploitation of this issue… | |
| Analizada | Media (6.2) | 0.49% | — | Adobe Coldfusion | 9/12/2025 | 25/9/2026 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. A high privileged attacker could exploit this vulnerability to access sensitive files and data on the server.… | |
| Analizada | Media (6.2) | 0.65% | — | Adobe Coldfusion | 9/12/2025 | 25/9/2026 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could exploit this vulnerability to write malicious files to arbitrary locations on the file system. Exploitation of this issue does not… | |
| Analizada | Media (6.8) | 0.53% | — | Adobe Coldfusion | 9/12/2025 | 25/9/2026 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and data on the server. Exploit depends on… | |
| Analizada | Alta (7.4) | 0.55% | — | Adobe Coldfusion | 9/12/2025 | 25/9/2026 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the server. Exploitation of this issue does… | |
| Analizada | Alta (8.4) | 4.7% | — | Adobe Coldfusion | 9/12/2025 | 25/9/2026 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution. Exploitation of this issue does not require user interaction. | |
| Modificada | Crítica (9.1) | 1.2% | — | Adobe Coldfusion | 9/12/2025 | 25/9/2026 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could leverage this vulnerability to bypass security measures and execute malicious code.… |