Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.30% | — | Hsweb-frameworkAI | 8/6/2026 | 23/7/2026 | A vulnerability was detected in hs-web hsweb-framework up to 5.0.1. This affects the function OAuth2Client of the file hsweb-authorization/hsweb-authorization-oauth2/src/main/java/org/hswebframework/web/oauth2/server/OAuth2Client.java of the component OAuth2 Client. The manipulation results in open redirect. The… | |
| Aplazada | Baja (2.1) | 0.30% | — | Hsweb-frameworkAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in hs-web hsweb-framework up to 5.0.1. The affected element is the function denied of the file hsweb-system/hsweb-system-file/src/main/java/org/hswebframework/web/file/FileUploadProperties.java of the component File Upload. The manipulation of the argument filename leads to path… | |
| Aplazada | Alta (7) | 0.66% | — | NanobotAIMicrosoft TeamsAIMicrosoft BOT FrameworkAI | 1/6/2026 | 22/7/2026 | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation… | |
| Aplazada | Baja (2.1) | 0.28% | — | Westboy CicadascmsAISpringframework CacheAI | 30/5/2026 | 22/7/2026 | A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractCacheManager.java. This manipulation of the argument s causes cross site scripting. Remote exploitation of the attack is possible. The… | |
| Analizada | Crítica (9.3) | 0.38% | — | Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+4 | 27/5/2026 | 17/6/2026 | The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. | |
| Aplazada | Alta (7.1) | 0.18% | — | Ricetheme Felan FrameworkAI | 27/5/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RiceTheme Felan Framework allows Reflected XSS. This issue affects Felan Framework: from n/a through 1.1.3. | |
| Aplazada | Media (6.4) | 0.32% | — | WP Iframe GEO Style FOR Amazon AffiliatesAI | 27/5/2026 | 17/6/2026 | The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Analizada | Alta (8.6) | 0.14% | — | Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+11 | 25/5/2026 | 17/8/2026 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.… | |
| Aplazada | Alta (7.4) | 0.50% | — | Yiiframework YIIAI | 20/5/2026 | 23/7/2026 | Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. The function calls extract($_params_, EXTR_OVERWRITE) before the require statement that loads the view file. As a result, a caller-controlled… | |
| Analizada | Alta (8.8) | 0.76% | — | Nvidia Bionemo Framework | 20/5/2026 | 23/7/2026 | NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering. | |
| Analizada | Alta (7.8) | 0.29% | — | Nvidia Bionemo Framework | 20/5/2026 | 23/7/2026 | NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering. | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory resulting in loss of confidentiality or availability. | |
| Pendiente de análisis | Alta (7.1) | 0.11% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial of service or arbitrary code execution. | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory location potentially resulting in loss of availability or confidentiality. | |
| Pendiente de análisis | Alta (8.4) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or allowing privilege escalation resulting in loss of confidentiality. | |
| Pendiente de análisis | Alta (8.4) | 0.11% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary code at an elevated privilege level potentially leading to loss of confidentiality integrity, or availability. | |
| Pendiente de análisis | Alta (8.3) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address potentially resulting in loss of confidentiality, integrity, or availability. | |
| Pendiente de análisis | Alta (8.5) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege escalation. | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information disclosure or a crash | |
| Pendiente de análisis | Alta (8.5) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting in privilege escalation | |
| Aplazada | Media (4.6) | 0.23% | — | EFW Enterprise Framework FOR WEBAI | 12/5/2026 | 17/6/2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME type based on file extension, without any content sanitization or security headers. Files with .html, .htm, or .svg extensions are served as text/html or image/svg+xml respectively, causing any… | |
| Aplazada | Baja (3.7) | 0.33% | — | Micronaut FrameworkAI | 12/5/2026 | 17/6/2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Prior to 4.10.22, the bundleCache is keyed by (Locale, baseName) where the locale originates from the HTTP Accept-Language header. In applications that explicitly register a… | |
| Aplazada | Alta (7.5) | 0.72% | — | Micronaut FrameworkAI | 12/5/2026 | 10/7/2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, 3.10.6, and 3.8.14, TimeConverterRegistrar caches DateTimeFormatter instances in an unbounded ConcurrentHashMap<String, DateTimeFormatter> whose key is derived… | |
| Modificada | Alta (7.3) | 0.57% | — | Microsoft .net FrameworkMicrosoft .net | 12/5/2026 | 15/7/2026 | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | |
| Modificada | Alta (7.3) | 0.57% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net | 12/5/2026 | 15/7/2026 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. |