Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.33%—Oracle Subledger Accounting17/6/202618/6/2026
Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Subledger Accounting.…
AnalizadaAlta (7.5)0.33%—Oracle Subledger Accounting17/6/202618/6/2026
Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Subledger Accounting.…
AnalizadaCrítica (9.9)0.43%—Oracle JD Edwards Enterpriseone Accounts Payable17/6/202618/6/2026
Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Accounts Payable.…
AnalizadaAlta (8.1)0.36%—Oracle JD Edwards Enterpriseone Accounts Payable17/6/202626/6/2026
Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Accounts Payable.…
AplazadaMedia (4.3)0.22%—Bizswoop Account Manager FOR WoocommerceAI27/5/202617/6/2026
Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Account Manager for WooCommerce: from n/a through 2.1.2.
AplazadaAlta (8.8)0.52%—Account SwitcherAI20/5/202624/7/2026
The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` REST API endpoint using a loose comparison (`!=` instead of `!==`) for secret validation at `app/RestAPI.php:111`, combined with no validation that the secret…
AplazadaMedia (5.5)0.41%—Code-projects Accounting SystemAI30/3/202617/6/2026
A security vulnerability has been detected in code-projects Accounting System 1.0. This issue affects some unknown processing of the file /viewin_costumer.php of the component Parameter Handler. Such manipulation of the argument cos_id leads to sql injection. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (5.5)0.57%—Sherlock Accounting System29/3/202617/6/2026
A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Parameter Handler. Such manipulation of the argument en_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (5.5)0.55%—Sherlock Accounting System29/3/202617/6/2026
A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation of the argument cos_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (5.5)0.57%—Sherlock Accounting System29/3/202617/6/2026
A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Parameter Handler. The manipulation of the argument cos_id results in sql injection. The attack may be performed from remote. The exploit is…
AplazadaBaja (2.1)0.32%—Code-projects Accounting SystemAI26/3/202617/6/2026
A vulnerability was detected in code-projects Accounting System 1.0. The affected element is an unknown function of the file /my_account/delete.php. Performing a manipulation of the argument cos_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
AplazadaBaja (2)0.33%—Code-projects Accounting SystemAI26/3/202617/6/2026
A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface. Such manipulation of the argument costumer_name leads to cross site scripting. The attack may be performed from remote.…
AnalizadaAlta (8.8)0.77%—Ldap-account-manager Ldap Account Manager18/3/202617/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf,…
AnalizadaAlta (8.8)0.67%—Ldap-account-manager Ldap Account Manager18/3/202617/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local file inclusion was detected in the PDF export that allows users to include local PHP files and this way execute code. In combination with GHSA-88hf-2cjm-m9g8…
AnalizadaMedia (6.9)0.12%—Samsung Account16/3/202617/6/2026
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
AnalizadaCrítica (9.1)0.45%—Telekom Account Management Portal10/3/202617/6/2026
Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-24, fixed 2025-11-03.
AnalizadaCrítica (9.4)0.39%—Telekom Account Management Portal10/3/202617/6/2026
Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-27, fixed 2025-10-31.
AplazadaAlta (8.6)0.31%—Zirve Information Technologies INC E-taxpayer Accounting WebsiteAI9/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. E-Taxpayer Accounting Website allows Reflected XSS. This issue affects e-Taxpayer Accounting Website: through 07082025.
AnalizadaMedia (5.1)0.24%—Mybb Delete Account23/1/202617/6/2026
MyBB Delete Account Plugin 1.4 contains a cross-site scripting vulnerability in the account deletion reason input field. Attackers can inject malicious scripts that will execute in the admin interface when viewing delete account reasons.
AnalizadaMedia (6.1)0.42%—Microsoft Account22/1/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.
AplazadaAlta (8.5)0.15%—OKI Print JOB AccountingAI21/1/202617/6/2026
OKI Print Job Accounting 4.4.10 contains an unquoted service path vulnerability in the OkiJaSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Print Job Accounting\' to inject malicious executables and escalate privileges.
AplazadaAlta (7.2)0.39%—Silverplugins217 Custom-fields-account-registration-for-woocommerceAI18/12/202517/6/2026
Incorrect Privilege Assignment vulnerability in silverplugins217 Custom Fields Account Registration For Woocommerce custom-fields-account-registration-for-woocommerce allows Privilege Escalation.This issue affects Custom Fields Account Registration For Woocommerce: from n/a through <= 1.2.
AnalizadaBaja (3.3)0.15%—Samsung Account2/12/202517/6/2026
Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege.
AnalizadaMedia (5.5)0.19%—Samsung Account2/12/202525/9/2026
Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.
AnalizadaMedia (6.1)0.26%—Remyandrade Modern User Account Generator7/11/202517/6/2026
Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute arbitrary JavaScript code in the context of the user's browser session via crafted input in the Username Prefix field. The vulnerability exists due to improper sanitization of user-supplied input…
Orbitaley — Vulnerabilidades