Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1090 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.44% | — | Magepeople Booking & Rental Manager | 23/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Booking and Rental Manager for Bike plugin <= 1.2.1 versions. | |
| Modificada | Media (5.4) | 0.51% | — | Codepeople Contact Form Email | 12/6/2023 | 17/6/2026 | The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability. | |
| Modificada | Alta (8.8) | 0.29% | — | Mage-people Event Manager AND Tickets Selling Plugin FOR Woocommerce | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.7.7 versions. | |
| Modificada | Media (5.4) | 0.41% | — | Oracle Peoplesoft Enterprise Human Capital Management Human Resources | 18/4/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Administer Workforce). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Modificada | Media (4.9) | 0.63% | — | Oracle Peoplesoft Enterprise Peopletools | 18/4/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Media (5.3) | 0.51% | — | Oracle Peoplesoft Enterprise Peopletools | 18/4/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Web Server). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Crítica (9.8) | 1.0% | — | Codepeople CP Appointment Calendar | 10/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dex_process_ready_to_go_appointment of the file dex_appointments.php. The manipulation of the argument itemnumber leads to sql injection. It is possible to initiate the attack… | |
| Modificada | Media (4.8) | 0.39% | — | Codepeople WP Time Slots Booking Form | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CodePeople WP Time Slots Booking Form plugin <= 1.1.81 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 23/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions. | |
| Modificada | Crítica (9.8) | 0.79% | — | Codepeople Polls CP | 4/3/2023 | 17/6/2026 | A vulnerability has been found in codepeople cp-polls Plugin 1.0.1 on WordPress and classified as critical. This vulnerability affects unknown code of the file cp-admin-int-message-list.inc.php. The manipulation of the argument lu leads to sql injection. The attack can be initiated remotely. Upgrading to version 1.0.2… | |
| Modificada | Media (6.5) | 0.24% | — | A3rev Contact US Page - Contact People | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Contact Us Page – Contact People plugin <= 3.7.0. | |
| Modificada | Media (5.4) | 0.48% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 6/2/2023 | 17/6/2026 | The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.40% | — | Oracle Peoplesoft Enterprise Peopletools | 18/1/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). The supported version that is affected is 8.60. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Modificada | Media (5.4) | 0.38% | — | Oracle Peoplesoft Enterprise Peopletools | 18/1/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Media (5.3) | 0.51% | — | Oracle Peoplesoft Enterprise CS Academic Advisement | 18/1/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CS Academic Advisement product of Oracle PeopleSoft (component: Advising Notes). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Academic… | |
| Modificada | Alta (8.8) | 0.54% | — | Codepeople Appointment Booking Calendar | 18/11/2022 | 17/6/2026 | Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress. | |
| Modificada | Media (5.5) | 0.26% | — | Oracle Peoplesoft Enterprise Peopletools | 18/10/2022 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to… | |
| Modificada | Alta (8.1) | 0.70% | — | Oracle Peoplesoft Enterprise Common Components | 18/10/2022 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise Common Components product of Oracle PeopleSoft (component: Approval Framework). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise Common Components.… | |
| Modificada | Media (6.1) | 0.55% | — | Oracle Peoplesoft Enterprise | 18/10/2022 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search Integration). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (5.3) | 0.65% | — | Oracle Peoplesoft Enterprise | 18/10/2022 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Media (4.8) | 0.63% | — | Codepeople Form Builder CP | 19/9/2022 | 17/6/2026 | The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 1.5% | — | Oracle Peoplesoft Enterprise Peopletools | 19/7/2022 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mgmt). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (4.9) | 0.81% | — | Oracle Peoplesoft Enterprise Peopletools | 19/7/2022 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XML Publisher). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Media (6.1) | 0.65% | — | Oracle Peoplesoft Enterprise Peopletools | 19/7/2022 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Modificada | Media (4.4) | 0.24% | — | Oracle Peoplesoft Enterprise Peopletools | 19/7/2022 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes… |