Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.11% | — | Fabasoft Folio ClientAIFabasoft Egov-suiteAI | 24/9/2026 | 26/9/2026 | Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default,… | |
| Aplazada | Alta (8.1) | 0.47% | — | Thegov CoreAI | 17/6/2026 | 17/6/2026 | Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions. | |
| Aplazada | Alta (8.7) | 0.27% | — | Egovframe-common-componentsAI | 19/11/2025 | 14/7/2026 | eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and related file delivery functionality that uses symmetric encryption to protect URL parameters, but exposes an encryption oracle that allows attackers to generate valid ciphertext for chosen values. The… | |
| Aplazada | Media (6.9) | 0.56% | — | Egovframework Egovframe-common-componentsAI | 19/11/2025 | 14/7/2026 | eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vulnerability via the /utl/wed/insertImage.do and /utl/wed/insertImageCk.do image upload endpoints. These controllers accept multipart requests without authentication, pass the uploaded content to a… | |
| Analizada | Media (5.7) | 0.43% | — | Nukeviet EgovernmentNukeviet | 10/6/2024 | 17/6/2026 | nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component. | |
| Analizada | Alta (8.8) | 0.84% | — | Nukeviet EgovernmentNukeviet | 10/6/2024 | 17/6/2026 | nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php. | |
| Modificada | Alta (7.8) | 0.19% | — | Fabasoft CloudFabasoft Cloud Enterprise ClientFabasoft Folio / Egov-suite | 3/8/2023 | 17/6/2026 | Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator. | |
| Modificada | Alta (7.5) | 10% | — | Newgensoft Egov | 30/12/2020 | 17/6/2026 | In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference. | |
| Modificada | Media (4.3) | 1.2% | — | Egov Manger | 5/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in eGov Manager allow remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied input" to (1) center.exe or (2) Index.exe. |