Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1090 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.42% | — | Codepeople CP PollsAI | 17/5/2024 | 17/6/2026 | : Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71. | |
| Analizada | Media (4.9) | 0.52% | — | Oracle Peoplesoft Enterprise Peopletools | 16/4/2024 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Media (5.4) | 0.33% | — | Oracle Peoplesoft Enterprise Peopletools | 16/4/2024 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Search Framework). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Media (6.1) | 0.34% | — | Oracle Peoplesoft Enterprise Peopletools | 16/4/2024 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Media (6.1) | 0.17% | — | Oracle Peoplesoft Enterprise HCM Benefits Administration | 16/4/2024 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Benefits Administration product of Oracle PeopleSoft (component: Benefits Administration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise HCM… | |
| Aplazada | Media (5.4) | 0.21% | — | Codepeople CP Media PlayerAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Media Player.This issue affects CP Media Player: from n/a through 1.1.3. | |
| Aplazada | Media (4.3) | 0.21% | — | Magepeople WptravellyAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team WpTravelly.This issue affects WpTravelly: from n/a through 1.6.0. | |
| Modificada | Media (5.3) | 0.47% | — | Codepeople Contact Form Email | 10/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from n/a through 1.3.44. | |
| Modificada | Media (6.1) | 0.42% | — | Codepeople Calculated Fields Form | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Calculated Fields Form allows Reflected XSS.This issue affects Calculated Fields Form: from n/a through 1.2.54. | |
| Modificada | Alta (8.8) | 0.50% | — | Codepeople Google Maps CP | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople Google Maps CP.This issue affects Google Maps CP: from n/a through 1.0.43. | |
| Analizada | Alta (8.8) | 0.38% | — | Codepeople Appointment Booking Calendar | 20/3/2024 | 17/6/2026 | The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying. | |
| Modificada | Media (6.1) | 0.58% | — | Codepeople Calculated Fields Form | 13/3/2024 | 17/6/2026 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href parameter in all versions up to, and including, 5.1.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Alta (8.8) | 0.50% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 12/2/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin: from n/a through 4.1.1. | |
| Modificada | Media (5.4) | 0.48% | — | Codepeople Calculated Fields Form | 2/2/2024 | 17/6/2026 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULATED_FIELDS shortcode in all versions up to, and including, 1.2.52 due to insufficient input sanitization and output escaping on user supplied 'location' attribute. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.47% | — | Codepeople WP Time Slots Booking Form | 17/1/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76. | |
| Modificada | Media (4.8) | 0.47% | — | Codepeople Calculated Fields Form | 16/1/2024 | 17/6/2026 | The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.29% | — | Codepeople Calculated Fields Form | 29/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28. | |
| Modificada | Media (4.8) | 0.46% | — | Codepeople Contact Form Email | 11/12/2023 | 17/6/2026 | The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.40% | — | Mage-people BUS Ticket Booking With Seat Reservation | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MagePeople Team WpBusTicketly plugin <= 5.2.5 versions. | |
| Modificada | Media (6.5) | 0.53% | — | Oracle Peoplesoft Enterprise Cost Center Common Application Objects | 17/10/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Events & Notifications). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC… | |
| Modificada | Media (6.1) | 0.39% | — | Oracle Peoplesoft Enterprise Peopletools | 17/10/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Media (6.1) | 0.43% | — | Mage-people BUS Ticket Booking With Seat Reservation | 2/8/2023 | 17/6/2026 | The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modificada | Alta (7.5) | 77% | 💥 Exploit | Oracle Peoplesoft Enterprise | 18/7/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Modificada | Alta (8.4) | 0.21% | — | Oracle Peoplesoft Enterprise Peopletools | 18/7/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to… | |
| Modificada | Media (5.4) | 0.33% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 18/7/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions. |