Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1833 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.31%—Automattic Jetpack Debug ToolsAI15/5/202517/6/2026
Missing Authorization vulnerability in Automattic Jetpack Debug Tools.This issue affects Jetpack Debug Tools: from n/a before 2.0.1.
AplazadaMedia (6.6)0.19%—Net-toolsAI14/5/202517/6/2026
net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to and including 2.10, the Linux network utilities (like ifconfig) from the net-tools package do not properly validate the structure of /proc files when showing interfaces.…
AnalizadaAlta (8)1.2%—Microsoft Build ToolsMicrosoft Visual Studio 2022Microsoft .net13/5/202517/6/2026
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
AplazadaMedia (5.4)0.14%—Intel Network Adapters Administrative ToolsAI13/5/202517/6/2026
Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.1)0.27%—Vmware ToolsAI12/5/202517/6/2026
VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.
AplazadaMedia (5.9)0.47%—Database ToolsetAI3/5/202517/6/2026
The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.4 via backup files stored in a publicly accessible location. This makes it possible for unauthenticated attackers to extract sensitive data from database backup files. An index file is…
AnalizadaMedia (6.9)0.56%—Scriptandtools Online Traveling System29/4/202517/6/2026
A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admin/viewpackage.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may…
AnalizadaMedia (6.9)0.60%—Scriptandtools Online Traveling System29/4/202517/6/2026
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/addpackage.php. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (6.9)0.51%—Scriptandtools Online Traveling System29/4/202517/6/2026
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/addadvertisement.php. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.9)0.56%—Scriptandtools Online Traveling System29/4/202517/6/2026
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/viewenquiry.php. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (6.9)0.77%—Scriptandtools Ecommerce-website-in-php27/4/202517/6/2026
A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of the file /admin/subscriber-csv.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public…
AnalizadaAlta (7.5)0.95%—Apache HttpclientNetapp Ontap Tools24/4/202517/6/2026
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
AplazadaCrítica (9.1)1.1%—Database ToolsetAI24/4/202517/6/2026
The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the…
AplazadaAlta (7.4)0.25%—Billminozzi WP ToolsAI16/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in sminozzi WP Tools wptools allows Path Traversal.This issue affects WP Tools: from n/a through <= 5.18.
AplazadaAlta (7.1)0.23%—Dzynit Seo-automatic-seo-toolsAI15/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dzynit SEO Tools seo-automatic-seo-tools allows Reflected XSS.This issue affects SEO Tools: from n/a through <= 4.0.7.
AnalizadaMedia (6.5)0.36%—Oracle JD Edwards Enterpriseone Tools15/4/202517/6/2026
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful…
AnalizadaMedia (6.1)0.41%—Oracle JD Edwards Enterpriseone Tools15/4/202517/6/2026
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful…
AnalizadaMedia (5.4)0.36%—Oracle Peoplesoft Enterprise Peopletools15/4/202517/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.…
AnalizadaMedia (5.4)0.36%—Oracle JD Edwards Enterpriseone Tools15/4/202517/6/2026
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful…
AnalizadaMedia (5.3)0.34%—Scriptandtools Ecommerce-website-in-php14/4/202517/6/2026
A vulnerability, which was classified as problematic, has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be…
AnalizadaMedia (6.3)0.99%—Scriptandtools Ecommerce-website-in-php14/4/202517/6/2026
A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely. The…
AnalizadaMedia (6.3)0.99%—Scriptandtools Ecommerce-website-in-php14/4/202517/6/2026
A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an unknown function of the file /login.php. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The complexity of an attack…
AnalizadaAlta (7.3)0.75%—Microsoft SQL Server Management StudioMicrosoft Visual Studio Tools FOR Applications 2019Microsoft Visual Studio Tools FOR Applications 2019 SDKMicrosoft Visual Studio Tools FOR Applications 2022+112/4/202517/6/2026
Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.
AplazadaAlta (8.6)0.78%—Neoslab Database ToolsetAI11/4/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in neoslab Database Toolset database-toolset allows Path Traversal.This issue affects Database Toolset: from n/a through <= 1.8.4.
AplazadaAlta (7.1)0.21%—Ab-tools Flags WidgetAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ab-tools Flags Widget flags-widget allows Stored XSS.This issue affects Flags Widget: from n/a through <= 1.0.7.
Orbitaley — Vulnerabilidades