Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.49% | — | Oracle Application Development Framework | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise… | |
| Aplazada | Alta (8.7) | 0.29% | — | CherryframeworkAI | 15/6/2026 | 17/6/2026 | WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive backup files by accessing the download_backup.php endpoint. Attackers can directly access the download_backup.php script in the admin/data_management directory to obtain… | |
| Aplazada | Media (5.9) | 0.18% | — | Membraneframework Membrane MP4 PluginAI | 11/6/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unauthenticated denial-of-service via BEAM atom table exhaustion. The MP4 box header parser converts each 4-byte box name to an atom using String.to_atom/1 without validation.… | |
| Analizada | Crítica (9.8) | 0.48% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring… | |
| Analizada | Media (6.5) | 0.21% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18. | |
| Analizada | Media (5.3) | 0.31% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | |
| Analizada | Media (5.3) | 0.26% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18;… | |
| Analizada | Alta (7.5) | 0.46% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0… | |
| Analizada | Alta (7.5) | 0.46% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability.… | |
| Analizada | Alta (7.5) | 0.46% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0… | |
| Analizada | Alta (7.5) | 0.40% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path),… | |
| Analizada | Media (5.3) | 0.26% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48. | |
| Analizada | Media (6.1) | 0.24% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through… | |
| Analizada | Media (6.1) | 0.28% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | |
| Analizada | Media (6.1) | 0.23% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through… | |
| Analizada | Media (5.9) | 0.39% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | |
| Analizada | Alta (7.5) | 0.46% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | |
| Analizada | Media (5.9) | 0.34% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | |
| Analizada | Media (5.9) | 0.37% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48. | |
| Analizada | Media (4.2) | 0.21% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0… | |
| Analizada | Alta (7.5) | 0.29% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | |
| Aplazada | Baja (2.1) | 0.30% | — | Hsweb-frameworkAI | 8/6/2026 | 23/7/2026 | A vulnerability was detected in hs-web hsweb-framework up to 5.0.1. This affects the function OAuth2Client of the file hsweb-authorization/hsweb-authorization-oauth2/src/main/java/org/hswebframework/web/oauth2/server/OAuth2Client.java of the component OAuth2 Client. The manipulation results in open redirect. The… | |
| Aplazada | Baja (2.1) | 0.30% | — | Hsweb-frameworkAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in hs-web hsweb-framework up to 5.0.1. The affected element is the function denied of the file hsweb-system/hsweb-system-file/src/main/java/org/hswebframework/web/file/FileUploadProperties.java of the component File Upload. The manipulation of the argument filename leads to path… | |
| Aplazada | Alta (7) | 0.66% | — | NanobotAIMicrosoft TeamsAIMicrosoft BOT FrameworkAI | 1/6/2026 | 22/7/2026 | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation… | |
| Aplazada | Baja (2.1) | 0.28% | — | Westboy CicadascmsAISpringframework CacheAI | 30/5/2026 | 22/7/2026 | A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractCacheManager.java. This manipulation of the argument s causes cross site scripting. Remote exploitation of the attack is possible. The… |