Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.11%—Fabasoft Folio ClientAIFabasoft Egov-suiteAI24/9/202626/9/2026
Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default,…
AplazadaAlta (8.1)0.47%—Thegov CoreAI17/6/202617/6/2026
Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions.
AplazadaAlta (8.7)0.27%—Egovframe-common-componentsAI19/11/202514/7/2026
eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and related file delivery functionality that uses symmetric encryption to protect URL parameters, but exposes an encryption oracle that allows attackers to generate valid ciphertext for chosen values. The…
AplazadaMedia (6.9)0.56%—Egovframework Egovframe-common-componentsAI19/11/202514/7/2026
eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vulnerability via the /utl/wed/insertImage.do and /utl/wed/insertImageCk.do image upload endpoints. These controllers accept multipart requests without authentication, pass the uploaded content to a…
AnalizadaMedia (5.7)0.43%—Nukeviet EgovernmentNukeviet10/6/202417/6/2026
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.
AnalizadaAlta (8.8)0.84%—Nukeviet EgovernmentNukeviet10/6/202417/6/2026
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.
ModificadaAlta (7.8)0.19%—Fabasoft CloudFabasoft Cloud Enterprise ClientFabasoft Folio / Egov-suite3/8/202317/6/2026
Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator.
ModificadaAlta (7.5)10%—Newgensoft Egov30/12/202017/6/2026
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.
ModificadaMedia (4.3)1.2%—Egov Manger5/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in eGov Manager allow remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied input" to (1) center.exe or (2) Index.exe.