Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.24% | — | Memberpress Corporate AccountsAI | 12/9/2026 | 14/9/2026 | The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like… | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | Canonical AccountsserviceAI | 20/8/2026 | 28/8/2026 | The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | Canonical AccountsserviceAI | 20/8/2026 | 28/8/2026 | An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to… | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | Systemd-homedAIFreedesktop AccountsserviceAI | 24/7/2026 | 24/7/2026 | A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process. | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle JD Edwards Enterpriseone Accounts Payable | 17/6/2026 | 18/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Accounts Payable.… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle JD Edwards Enterpriseone Accounts Payable | 17/6/2026 | 26/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Accounts Payable.… | |
| Aplazada | Media (6.5) | 0.21% | — | Renventura WP Delete User AccountsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ren Ventura WP Delete User Accounts wp-delete-user-accounts allows Stored XSS.This issue affects WP Delete User Accounts: from n/a through <= 1.2.4. | |
| Aplazada | Alta (8.8) | 0.52% | — | Mediaticus Subaccounts FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce subaccounts-for-woocommerce allows Authentication Abuse.This issue affects Subaccounts for WooCommerce: from n/a through <= 1.6.6. | |
| Aplazada | Media (6.5) | 0.27% | — | Renventura WP Delete User AccountsAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ren Ventura WP Delete User Accounts wp-delete-user-accounts allows DOM-Based XSS.This issue affects WP Delete User Accounts: from n/a through <= 1.2.3. | |
| Analizada | Media (5.5) | 0.14% | — | Canonical AccountsserviceCanonical Ubuntu Linux | 25/3/2025 | 17/6/2026 | accountsservice no longer drops permissions when writting .pam_environment | |
| Modificada | Media (6.1) | 0.60% | — | Mediaticus Subaccounts FOR Woocommerce | 21/11/2024 | 17/6/2026 | The Subaccounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (5.3) | 0.45% | — | Remyandrade Accounts Manager APP | 20/8/2024 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Accounts Manager App 1.0. This vulnerability affects unknown code of the file update-account.php of the component Update Account Page. The manipulation of the argument Account Name/Username/Password/Link leads to cross site scripting. The attack can… | |
| Analizada | Media (5.3) | 0.50% | — | Remyandrade Accounts Manager APP | 13/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Accounts Manager App 1.0. Affected is an unknown function of the file /endpoint/add-account.php. The manipulation of the argument account_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.66% | — | Remyandrade Accounts Manager APP | 13/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Accounts Manager App 1.0. This issue affects some unknown processing of the file /endpoint/delete-account.php. The manipulation of the argument account leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Baja (3.3) | 0.17% | — | Amazon Awslabs Sandbox Accounts FOR Events | 22/12/2023 | 17/6/2026 | Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially read data from the events table by sending request payloads to the events API, collecting information on planned events, timeframes,… | |
| Modificada | Crítica (9) | 0.38% | — | Amazon Awslabs Sandbox Accounts FOR Events | 22/12/2023 | 17/6/2026 | "Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially claim and access empty AWS accounts by sending request payloads to the account API containing non-existent event ids and self-defined… | |
| Modificada | Media (6.1) | 0.45% | — | Broadpeak Centralized Accounts Management Auth Agent | 3/10/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00.19219575_ee9195b0, 01.01.01.30097902_fd999e76, and 00.12.01.9565588_1254b459 allows remote attackers to inject arbitrary web script or HTML via the… | |
| Modificada | Alta (7.8) | 0.33% | — | Canonical AccountsserviceCanonical Ubuntu Linux | 1/9/2023 | 17/6/2026 | In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process. | |
| Modificada | Media (6.1) | 0.56% | — | Monitoring OF Students Cyber Accounts System Project Monitoring OF Students Cyber Accounts System | 18/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. Affected by this issue is some unknown functionality of the file modules/balance/index.php?view=balancelist of the component POST Parameter Handler. The manipulation of the argument… | |
| Modificada | Crítica (9.8) | 0.74% | — | Monitoring OF Students Cyber Accounts System Project Monitoring OF Students Cyber Accounts System | 18/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument un leads to sql injection. The attack can be… | |
| Modificada | Alta (7.8) | 0.37% | — | Canonical AccountsserviceCanonical Ubuntu Linux | 17/11/2021 | 17/6/2026 | Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus function. This is fixed in versions… | |
| Modificada | Media (6.5) | 0.76% | — | Nchsoftware Express Accounts | 28/12/2020 | 17/6/2026 | In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users. | |
| Modificada | Media (5.5) | 0.29% | — | Nchsoftware Express Accounts | 28/12/2020 | 17/6/2026 | NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file. | |
| Modificada | Media (5.5) | 0.41% | — | Freedesktop Accountsservice | 11/11/2020 | 17/6/2026 | An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location. | |
| Modificada | Baja (3.3) | 0.54% | 💥 PoC | Freedesktop Accountsservice | 11/11/2020 | 17/6/2026 | An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion. |