Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | IBM Atlas Ediscovery Process ManagementIBM Atlas SuiteIBM Disposal AND Governance Management FOR ITIBM Global Retention Policy AND Schedule Management | 10/1/2014 | 17/6/2026 | SQL injection vulnerability in IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) allows remote… | |
| Modificada | Media (6.4) | 1.4% | — | Sebastien Corbin Make Meeting Scheduler Module | 9/10/2013 | 16/6/2026 | The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to bypass intended access restrictions for a poll via a direct request to the node's URL instead of the hashed URL. | |
| Modificada | Media (6) | 1.1% | — | Simplenews Scheduler Project Simplenews Scheduler | 3/12/2012 | 16/6/2026 | The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by cron. | |
| Modificada | Media (5) | 1.2% | — | Nick Korbel Phpscheduleit | 24/9/2011 | 16/6/2026 | phpScheduleIt 1.2.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/schedule.template.php and certain other files. | |
| Modificada | Alta (7.5) | 1.4% | — | Hitachi Groupmax Groupware ServerHitachi Groupmax Scheduler Server SETHitachi Groupmax Server SET | 11/9/2009 | 16/6/2026 | Unspecified vulnerability in Hitachi Groupmax Groupware Server 07-00 through 07-50-/A, Groupmax Server Set 03-00 through 06-52, Groupware Server Set 03-00 through 06-52, and Scheduler Server Set 03-00 through 06-52 has unknown impact and attack vectors related to invalid access rights. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Php.brickhost Phpscheduleit | 5/3/2009 | 16/6/2026 | Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date parameter to reserve.php and (2) the start_date and end_date parameters to check.php. NOTE: the start_date/reserve.php vector is already covered by CVE-2008-6132. | |
| Modificada | Media (6.8) | 26% | 💥 Exploit | Brickhost Phpscheduleit | 13/2/2009 | 16/6/2026 | Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via the start_date parameter. | |
| Modificada | Media (6.8) | 1.9% | — | Brickhost Phpscheduleit | 24/7/2008 | 16/6/2026 | Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2.9, when useLogonName is enabled, allows remote attackers with administrator email address knowledge to bypass restrictions and gain privileges via unspecified vectors related to login names. NOTE: some of these details are obtained from third party… | |
| Modificada | Media (6.5) | 1.3% | — | Oracle Database SchedulerOracle Database Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the Database Scheduler component in Oracle Database 10.2.0.4 and 11.1.0.6 has unknown impact and local attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is an untrusted search path… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Postnuke Software Foundation Postschedule | 30/4/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the eid parameter in an event action. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Phpjobscheduler | 16/11/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter to (1) add-modify.php, (2) delete.php, (3) modify.php, and (4) phpjobscheduler.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpjobscheduler | 16/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in firepjs.php in Phpjobscheduler 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter. NOTE: the provenance of this information is unknown; details are obtained from third party sources. | |
| Modificada | Alta (7.5) | 1.3% | — | Maxxcode Maxxschedule | 9/5/2006 | 16/6/2026 | SQL injection vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to execute arbitrary SQL commands via the txtLogon parameter. | |
| Modificada | Baja (2.6) | 1.3% | — | Maxxcode Maxxschedule | 9/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to inject arbitrary web script or HTML via the Error parameter. | |
| Modificada | Media (5.8) | 1.3% | — | Hitachi Groupmax World Wide WEBHitachi Groupmax World Wide WEB DesktopHitachi Groupmax World Wide WEB Desktop SchedulerHitachi Groupmax World Wide WEB Scheduler | 1/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web, World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for Scheduler, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | |
| Modificada | Media (5) | 1.2% | — | Brickhost Phpscheduleit | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations. | |
| Modificada | Alta (7.5) | 1.1% | — | Brickhost Phpscheduleit | 31/8/2004 | 16/6/2026 | phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges. | |
| Modificada | Media (4.3) | 1.3% | — | Brickhost Phpscheduleit | 31/8/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field. | |
| Modificada | Alta (10) | 6.7% | 💥 Exploit | Crosswind Cyberscheduler | 2/7/2001 | 16/6/2026 | Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter. |