Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.49% | — | Cybrosys Techno Solutions Text CommanderAI | 6/5/2024 | 17/6/2026 | A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote attacker to gain privileges via the data parameter to models/ir_model.py:IrModel::chech_model. | |
| Aplazada | Media (5.9) | 0.36% | — | Alttext.ai Download ALT Text AIAI | 6/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AltText.Ai Download Alt Text AI allows Stored XSS.This issue affects Download Alt Text AI: from n/a through 1.3.4. | |
| Analizada | Alta (8.1) | 1.6% | — | Redhat Build OF KeycloakRedhat Jboss Middleware Text-only AdvisoriesRedhat KeycloakRedhat Migration Toolkit FOR Applications+6 | 17/4/2024 | 4/8/2026 | A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that… | |
| Aplazada | Alta (7.7) | 0.47% | — | Joris VAN Montfort JVM Rich Text IconsAI | 17/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Joris van Montfort JVM rich text icons.This issue affects JVM rich text icons: from n/a through 1.2.6. | |
| Aplazada | Media (6.5) | 0.31% | — | Flector Easy TextillateAI | 17/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flector Easy Textillate allows Stored XSS.This issue affects Easy Textillate: from n/a through 2.02. | |
| Aplazada | Alta (8.7) | 0.50% | — | Opentext Arcsight Management CenterAIOpentext Arcsight PlatformAI | 8/4/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited. | |
| Aplazada | Media (6.5) | 0.32% | — | Blocksmarket Gradient Text Widget FOR ElementorAI | 7/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blocksmarket Gradient Text Widget for Elementor allows Stored XSS.This issue affects Gradient Text Widget for Elementor: from n/a through 1.0.1. | |
| Aplazada | Alta (7.4) | 0.23% | — | Opentext Zenworks Configuration ManagementAI | 27/3/2024 | 17/6/2026 | Incorrect Authorization vulnerability in OpenText™ ZENworks Configuration Management (ZCM) allows Unauthorized Use of Device Resources.This issue affects ZENworks Configuration Management (ZCM) versions: 2020 update 3, 23.3, and 23.4. | |
| Aplazada | Media (6.4) | 0.33% | — | Easy TextillateAI | 26/3/2024 | 17/6/2026 | The Easy Textillate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'textillate' shortcode in all versions up to, and including, 2.01 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Opentext Pvcs Version ManagerAI | 21/3/2024 | 17/6/2026 | Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files. | |
| Aplazada | Crítica (9.8) | 0.70% | — | Opentext Pvcs Version ManagerAI | 21/3/2024 | 17/6/2026 | Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Opentext Arcsight PlatformAI | 20/3/2024 | 17/6/2026 | A potential vulnerability has been identified in OpenText ArcSight Platform. The vulnerability could be remotely exploited. | |
| Aplazada | Media (6.5) | 0.39% | — | Opentext Service Management Automation XAIOpentext Asset Management XAIOpentext Hybrid Cloud Management XAI | 19/3/2024 | 17/6/2026 | Misinterpretation of Input vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX), and OpenText™ Hybrid Cloud Management X (HCMX) products. The vulnerability could allow Input data manipulation.This issue affects Service Management Automation X (SMAX) versions: 2020.05,… | |
| Aplazada | Media (6.5) | 0.34% | — | Opentext Service Management Automation XAIOpentext Asset Management XAI | 19/3/2024 | 17/6/2026 | Insufficient Granularity of Access Control vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Service Management Automation X (SMAX) versions 2020.05, 2020.08, 2020.11, 2021.02,… | |
| Modificada | Crítica (9.8) | 0.32% | — | Opentext Vertica | 15/3/2024 | 17/6/2026 | Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests. The vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences. This issue impacts the following Vertica Management Console versions: 10.x… | |
| Analizada | Media (6.1) | 0.37% | — | Opentext Exceed Turbox | 13/3/2024 | 17/6/2026 | HTML injection in OpenText™ Exceed Turbo X affecting version 12.5.1. The vulnerability could result in Cross site scripting. | |
| Analizada | Crítica (9.8) | 0.27% | — | Opentext Exceed Turbox | 13/3/2024 | 17/6/2026 | Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys. | |
| Analizada | Alta (7.5) | 0.50% | — | Opentext Exceed Turbox | 13/3/2024 | 17/6/2026 | Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of restricted information in unauthenticated RPC. | |
| Analizada | Alta (7.5) | 0.70% | — | Opentext Netiq Privileged Account Manager | 13/3/2024 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged Account Manager: before 3.7.0.2. | |
| Analizada | Media (6.5) | 0.50% | — | Inisev Enhanced Text Widget | 11/3/2024 | 17/6/2026 | The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for… | |
| Aplazada | Media (5.8) | 0.17% | — | Opentext Documentum D2AI | 8/3/2024 | 17/6/2026 | CWE-1385 vulnerability in OpenText Documentum D2 affecting versions16.5.1 to CE 23.2. The vulnerability could allow upload arbitrary code and execute it on the client's computer. | |
| Aplazada | Media (4.3) | 0.52% | — | Opentext Arcsight Enterprise Security ManagerAI | 1/3/2024 | 17/6/2026 | A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited. | |
| Modificada | Media (6.1) | 0.51% | — | Opentext ALM Octane | 15/2/2024 | 4/8/2026 | Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Assistive Context-aware Toolkit | 14/2/2024 | 17/6/2026 | Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.43% | — | Opentext Appbuilder | 29/1/2024 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Server Side Request Forgery, Probe System Files. AppBuilder's XML processor is vulnerable to XML External Entity Processing (XXE), allowing an authenticated user to upload specially crafted XML files to… |