Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.18% | — | Membraneframework Membrane MP4 PluginAI | 11/6/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unauthenticated denial-of-service via BEAM atom table exhaustion. The MP4 box header parser converts each 4-byte box name to an atom using String.to_atom/1 without validation.… | |
| Aplazada | Media (6.9) | 0.15% | — | Praydog ReframeworkAI | 27/1/2026 | 17/6/2026 | An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 leads to a heap-buffer overflow when a recursive error occurs. | |
| Analizada | Media (4.7) | 0.24% | — | Theupdateframework Go-tuf | 27/1/2026 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. Starting in version 2.0.0 and prior to version 2.4.1, if an application accepts a map file… | |
| Analizada | Alta (7.5) | 0.22% | — | Theupdateframework Go-tuf | 22/1/2026 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification… | |
| Analizada | Alta (7.5) | 0.59% | — | Theupdateframework Go-tuf | 22/1/2026 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic… | |
| Aplazada | Alta (8.2) | 0.51% | — | Theupdateframework Go-tufAI | 1/10/2024 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", then the client should trace the delegations in the order "A" then "B" then "C" but it may incorrectly trace the… | |
| Modificada | Alta (8.8) | 0.57% | — | Theupdateframework Go-tuf | 5/5/2022 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for updating the metadata files for roles other than the root role. Specifically, checks for rollback attacks are not implemented correctly meaning an attacker can cause clients to install software that… | |
| Modificada | Alta (7.5) | 1.9% | — | Midasolutions Eframework | 24/7/2020 | 17/6/2026 | There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authentication parameters. | |
| Modificada | Alta (7.5) | 3.3% | — | Midasolutions Eframework | 24/7/2020 | 17/6/2026 | Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal. | |
| Modificada | Crítica (9.8) | 57% | — | Midasolutions Eframework | 24/7/2020 | 17/6/2026 | There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required. | |
| Modificada | Crítica (9.8) | 18% | — | Midasolutions Eframework | 24/7/2020 | 17/6/2026 | Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution. | |
| Modificada | Crítica (9.8) | 98% | — | Midasolutions Eframework | 24/7/2020 | 17/6/2026 | There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required. | |
| Modificada | Media (6.1) | 0.94% | — | Midasolutions Eframework | 24/7/2020 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0. | |
| Modificada | Media (5.4) | 0.56% | — | Midasolutions Eframework | 24/7/2020 | 17/6/2026 | Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0. | |
| Modificada | Crítica (9.8) | 2.1% | — | Fatfreeframework Fat-free Framework | 11/3/2020 | 17/6/2026 | In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GET, or $_POST) to the framework's Clear method. |