Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

244 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—IBM Atlas Ediscovery Process ManagementIBM Atlas SuiteIBM Disposal AND Governance Management FOR ITIBM Global Retention Policy AND Schedule Management10/1/201417/6/2026
SQL injection vulnerability in IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) allows remote…
ModificadaMedia (6.4)1.4%—Sebastien Corbin Make Meeting Scheduler Module9/10/201316/6/2026
The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to bypass intended access restrictions for a poll via a direct request to the node's URL instead of the hashed URL.
ModificadaMedia (6)1.1%—Simplenews Scheduler Project Simplenews Scheduler3/12/201216/6/2026
The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by cron.
ModificadaMedia (5)1.2%—Nick Korbel Phpscheduleit24/9/201116/6/2026
phpScheduleIt 1.2.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/schedule.template.php and certain other files.
ModificadaAlta (7.5)1.4%—Hitachi Groupmax Groupware ServerHitachi Groupmax Scheduler Server SETHitachi Groupmax Server SET11/9/200916/6/2026
Unspecified vulnerability in Hitachi Groupmax Groupware Server 07-00 through 07-50-/A, Groupmax Server Set 03-00 through 06-52, Groupware Server Set 03-00 through 06-52, and Scheduler Server Set 03-00 through 06-52 has unknown impact and attack vectors related to invalid access rights.
ModificadaAlta (7.5)4.9%💥 ExploitPhp.brickhost Phpscheduleit5/3/200916/6/2026
Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date parameter to reserve.php and (2) the start_date and end_date parameters to check.php. NOTE: the start_date/reserve.php vector is already covered by CVE-2008-6132.
ModificadaMedia (6.8)26%💥 ExploitBrickhost Phpscheduleit13/2/200916/6/2026
Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via the start_date parameter.
ModificadaMedia (6.8)1.9%—Brickhost Phpscheduleit24/7/200816/6/2026
Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2.9, when useLogonName is enabled, allows remote attackers with administrator email address knowledge to bypass restrictions and gain privileges via unspecified vectors related to login names. NOTE: some of these details are obtained from third party…
ModificadaMedia (6.5)1.3%—Oracle Database SchedulerOracle Database Server15/7/200816/6/2026
Unspecified vulnerability in the Database Scheduler component in Oracle Database 10.2.0.4 and 11.1.0.6 has unknown impact and local attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is an untrusted search path…
ModificadaAlta (7.5)1.1%💥 ExploitPostnuke Software Foundation Postschedule30/4/200816/6/2026
SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the eid parameter in an event action.
ModificadaAlta (7.5)4.3%💥 ExploitPhpjobscheduler16/11/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter to (1) add-modify.php, (2) delete.php, (3) modify.php, and (4) phpjobscheduler.php.
ModificadaAlta (7.5)1.3%—Phpjobscheduler16/11/200616/6/2026
PHP remote file inclusion vulnerability in firepjs.php in Phpjobscheduler 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
ModificadaAlta (7.5)1.3%—Maxxcode Maxxschedule9/5/200616/6/2026
SQL injection vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to execute arbitrary SQL commands via the txtLogon parameter.
ModificadaBaja (2.6)1.3%—Maxxcode Maxxschedule9/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to inject arbitrary web script or HTML via the Error parameter.
ModificadaMedia (5.8)1.3%—Hitachi Groupmax World Wide WEBHitachi Groupmax World Wide WEB DesktopHitachi Groupmax World Wide WEB Desktop SchedulerHitachi Groupmax World Wide WEB Scheduler1/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web, World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for Scheduler, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
ModificadaMedia (5)1.2%—Brickhost Phpscheduleit31/12/200416/6/2026
Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.
ModificadaAlta (7.5)1.1%—Brickhost Phpscheduleit31/8/200416/6/2026
phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.
ModificadaMedia (4.3)1.3%—Brickhost Phpscheduleit31/8/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field.
ModificadaAlta (10)6.7%💥 ExploitCrosswind Cyberscheduler2/7/200116/6/2026
Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter.
Orbitaley — Vulnerabilidades