Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.70% | — | Mixphp FrameworkAI | 1/5/2026 | 17/6/2026 | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the FileHandler object. | |
| Aplazada | Crítica (9.8) | 0.70% | — | Mixphp FrameworkAI | 1/5/2026 | 17/6/2026 | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the RedisHandler object. | |
| Analizada | Media (5.3) | 0.34% | — | Vmware Spring Framework | 29/4/2026 | 17/6/2026 | Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep… | |
| Analizada | Baja (3.1) | 0.24% | — | Vmware Spring Framework | 29/4/2026 | 17/6/2026 | Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the… | |
| Analizada | Media (6.5) | 0.34% | — | Vmware Spring Framework | 29/4/2026 | 17/6/2026 | A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected. | |
| Aplazada | Media (6.3) | 0.51% | — | Data Sharing FrameworkAI | 21/4/2026 | 17/6/2026 | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS and Metadata Document caches used an inverted time comparison (isBefore instead of isAfter), causing the cache to never return cached values. Every incoming request… | |
| Aplazada | Media (6.8) | 0.22% | — | Data Sharing FrameworkAI | 21/4/2026 | 17/6/2026 | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This vulnerability is… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Application Development Framework | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Application… | |
| Analizada | Media (4.7) | 0.29% | — | Oracle Applications Framework | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Aplazada | Alta (8.7) | 0.57% | — | Mcp-frameworkAI | 16/4/2026 | 17/6/2026 | mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRequestBody() function in the HTTP transport concatenates request body chunks into a string with no size limit. Although a maxMessageSize configuration value exists, it is never enforced in… | |
| Aplazada | Media (5.3) | 0.40% | — | Silverstripe Assets ModuleAISilverstripe FrameworkAI | 16/4/2026 | 17/6/2026 | The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which bypasses file… | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft .netMicrosoft .net Framework | 14/4/2026 | 25/7/2026 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (5.9) | 0.66% | — | Microsoft .net Framework | 14/4/2026 | 25/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| Modificada | Alta (7.5) | 1.3% | — | Microsoft .net Framework | 14/4/2026 | 15/7/2026 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| Aplazada | Alta (7.1) | 0.19% | — | Adianti FrameworkAI | 12/4/2026 | 17/6/2026 | Adianti Framework 5.5.0 and 5.6.0 contains an SQL injection vulnerability that allows authenticated users to manipulate database queries by injecting SQL code through the name field in SystemProfileForm. Attackers can submit crafted SQL statements in the profile edit endpoint to modify user credentials and gain… | |
| Analizada | Alta (8.5) | 0.30% | — | Circl AIL Framework | 8/4/2026 | 24/7/2026 | AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality. When item content longer than 800 characters was processed, attacker-controlled content was returned… | |
| Aplazada | Media (5.5) | 0.69% | — | Heriklyma CppwebframeworkAI | 6/4/2026 | 17/6/2026 | A vulnerability was detected in HerikLyma CPPWebFramework up to 3.1. This issue affects some unknown processing. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue… | |
| Analizada | Alta (8.2) | 0.52% | — | Ash-hq ASH Framework | 2/4/2026 | 24/7/2026 | Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 unconditionally creates a new Erlang atom via Module.concat([value]) for any user-supplied binary string that starts with "Elixir.", before verifying whether the referenced… | |
| Analizada | Alta (8.8) | 0.31% | — | Nvidia Bionemo Framework | 31/3/2026 | 24/7/2026 | NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering. | |
| Analizada | Crítica (9.8) | 0.47% | — | Nvidia Bionemo Framework | 31/3/2026 | 24/7/2026 | NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering. | |
| Analizada | Media (6.5) | 0.40% | — | Opensecurity Mobile Security Framework | 26/3/2026 | 17/6/2026 | MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `mobsf/MobSF/utils.py` (lines 542-566) uses Python string formatting (`%`) to construct SQL queries with table names read from a SQLite database's `sqlite_master` table. When a security analyst uses… | |
| Aplazada | Alta (7.1) | 0.25% | — | G5theme Darna FrameworkAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Darna Framework darna-framework allows Reflected XSS.This issue affects Darna Framework: from n/a through <= 2.9. | |
| Aplazada | Alta (7.1) | 0.25% | — | G5theme Wolverine FrameworkAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Wolverine Framework wolverine-framework allows Reflected XSS.This issue affects Wolverine Framework: from n/a through <= 1.9. | |
| Aplazada | Alta (7.1) | 0.23% | — | G5theme Handmade FrameworkAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Handmade Framework handmade-framework allows Reflected XSS.This issue affects Handmade Framework: from n/a through <= 3.9. | |
| Analizada | Media (5.9) | 0.39% | — | Vmware Spring Framework | 20/3/2026 | 17/6/2026 | Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16,… |