Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.18%—Membraneframework Membrane MP4 PluginAI11/6/202617/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unauthenticated denial-of-service via BEAM atom table exhaustion. The MP4 box header parser converts each 4-byte box name to an atom using String.to_atom/1 without validation.…
AplazadaMedia (6.9)0.15%—Praydog ReframeworkAI27/1/202617/6/2026
An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 leads to a heap-buffer overflow when a recursive error occurs.
AnalizadaMedia (4.7)0.24%—Theupdateframework Go-tuf27/1/202617/6/2026
go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. Starting in version 2.0.0 and prior to version 2.4.1, if an application accepts a map file…
AnalizadaAlta (7.5)0.22%—Theupdateframework Go-tuf22/1/202617/6/2026
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification…
AnalizadaAlta (7.5)0.59%—Theupdateframework Go-tuf22/1/202617/6/2026
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic…
AplazadaAlta (8.2)0.51%—Theupdateframework Go-tufAI1/10/202417/6/2026
go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", then the client should trace the delegations in the order "A" then "B" then "C" but it may incorrectly trace the…
ModificadaAlta (8.8)0.57%—Theupdateframework Go-tuf5/5/202217/6/2026
go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for updating the metadata files for roles other than the root role. Specifically, checks for rollback attacks are not implemented correctly meaning an attacker can cause clients to install software that…
ModificadaAlta (7.5)1.9%—Midasolutions Eframework24/7/202017/6/2026
There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authentication parameters.
ModificadaAlta (7.5)3.3%—Midasolutions Eframework24/7/202017/6/2026
Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
ModificadaCrítica (9.8)57%—Midasolutions Eframework24/7/202017/6/2026
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.
ModificadaCrítica (9.8)18%—Midasolutions Eframework24/7/202017/6/2026
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.
ModificadaCrítica (9.8)98%—Midasolutions Eframework24/7/202017/6/2026
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.
ModificadaMedia (6.1)0.94%—Midasolutions Eframework24/7/202017/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.
ModificadaMedia (5.4)0.56%—Midasolutions Eframework24/7/202017/6/2026
Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.
ModificadaCrítica (9.8)2.1%—Fatfreeframework Fat-free Framework11/3/202017/6/2026
In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GET, or $_POST) to the framework's Clear method.