Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.53% | — | Haulmont Cuba PlatformAI | 22/4/2025 | 17/6/2026 | CUBA Platform is a high level framework for enterprise applications development. Prior to version 7.2.23, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing the server to run out of space and… | |
| Analizada | Media (6.5) | 0.69% | — | Haulmont Cuba PlatformHaulmont Cuba Rest APIHaulmont Jmix FrameworkHaulmont JPA WEB API | 22/4/2025 | 17/6/2026 | Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing… | |
| Analizada | Media (5.4) | 0.36% | — | Haulmont Cuba PlatformHaulmont Cuba Rest APIHaulmont Jmix FrameworkHaulmont JPA WEB API | 22/4/2025 | 17/6/2026 | Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the input parameter, which consists of a file path and name, can be manipulated to return the Content-Type header with text/html if the name part ends with .html. This could… | |
| Modificada | Media (5.4) | 0.67% | — | Haulmont Cuba PlatformHaulmont Reporting | 3/1/2019 | 17/6/2026 | The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "Reports > Reports" name field. |