Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.38% | — | Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+4 | 27/5/2026 | 17/6/2026 | The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. | |
| Aplazada | Alta (7.1) | 0.18% | — | Ricetheme Felan FrameworkAI | 27/5/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RiceTheme Felan Framework allows Reflected XSS. This issue affects Felan Framework: from n/a through 1.1.3. | |
| Analizada | Alta (8.6) | 0.14% | — | Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+11 | 25/5/2026 | 17/8/2026 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.… | |
| Aplazada | Alta (7.4) | 0.50% | — | Yiiframework YIIAI | 20/5/2026 | 23/7/2026 | Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. The function calls extract($_params_, EXTR_OVERWRITE) before the require statement that loads the view file. As a result, a caller-controlled… | |
| Analizada | Alta (8.8) | 0.76% | — | Nvidia Bionemo Framework | 20/5/2026 | 23/7/2026 | NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering. | |
| Analizada | Alta (7.8) | 0.29% | — | Nvidia Bionemo Framework | 20/5/2026 | 23/7/2026 | NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering. | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory resulting in loss of confidentiality or availability. | |
| Pendiente de análisis | Alta (7.1) | 0.11% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial of service or arbitrary code execution. | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory location potentially resulting in loss of availability or confidentiality. | |
| Pendiente de análisis | Alta (8.4) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or allowing privilege escalation resulting in loss of confidentiality. | |
| Pendiente de análisis | Alta (8.4) | 0.11% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary code at an elevated privilege level potentially leading to loss of confidentiality integrity, or availability. | |
| Pendiente de análisis | Alta (8.3) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address potentially resulting in loss of confidentiality, integrity, or availability. | |
| Pendiente de análisis | Alta (8.5) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege escalation. | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information disclosure or a crash | |
| Pendiente de análisis | Alta (8.5) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting in privilege escalation | |
| Aplazada | Media (4.6) | 0.23% | — | EFW Enterprise Framework FOR WEBAI | 12/5/2026 | 17/6/2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME type based on file extension, without any content sanitization or security headers. Files with .html, .htm, or .svg extensions are served as text/html or image/svg+xml respectively, causing any… | |
| Aplazada | Baja (3.7) | 0.33% | — | Micronaut FrameworkAI | 12/5/2026 | 17/6/2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Prior to 4.10.22, the bundleCache is keyed by (Locale, baseName) where the locale originates from the HTTP Accept-Language header. In applications that explicitly register a… | |
| Aplazada | Alta (7.5) | 0.72% | — | Micronaut FrameworkAI | 12/5/2026 | 10/7/2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, 3.10.6, and 3.8.14, TimeConverterRegistrar caches DateTimeFormatter instances in an unbounded ConcurrentHashMap<String, DateTimeFormatter> whose key is derived… | |
| Modificada | Alta (7.3) | 0.57% | — | Microsoft .net FrameworkMicrosoft .net | 12/5/2026 | 15/7/2026 | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | |
| Modificada | Alta (7.3) | 0.57% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net | 12/5/2026 | 15/7/2026 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Media (5.3) | 0.18% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers. | |
| Aplazada | Alta (8.7) | 0.52% | — | Phoenixframework PhoenixAI | 5/5/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix allows a denial of service via the long-poll transport's NDJSON body handling. In 'Elixir.Phoenix.Transports.LongPoll':publish/4, when a POST request is received with Content-Type: application/x-ndjson, the request body is… | |
| Aplazada | Alta (8.7) | 0.64% | — | Mtrudel BanditAIPhoenixframework PhoenixAIEmatia ElixirAI | 1/5/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The fragment reassembly path in 'Elixir.Bandit.WebSocket.Connection':handle_frame/3 in lib/bandit/websocket/connection.ex appends every incoming Continuation{fin:… | |
| Aplazada | Media (6.5) | 0.33% | — | Mixphp FrameworkAI | 1/5/2026 | 17/6/2026 | SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `data` array to the data function in BuildHelper.php. |