Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.39% | — | Codesavory Knowledge Base Documentation & Wiki Plugin BasepressAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1. | |
| Aplazada | Media (5) | 0.35% | — | Basepress Knowledge Base Documentation Wiki PluginAI | 29/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1. | |
| Aplazada | Alta (8.7) | 0.46% | — | Echo Plugins Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 27/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Echo Plugins Knowledge Base for Documentation, FAQs with AI Assistance.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through 11.30.2. | |
| Analizada | Media (6.1) | 0.44% | — | Public Knowledge Project Open Journal Systems | 1/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function. | |
| Modificada | Media (5.4) | 0.27% | — | Oracle Knowledge Management | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Knowledge Management.… | |
| Modificada | Media (6.1) | 0.31% | — | Oracle Knowledge Management | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful… | |
| Modificada | Media (6.1) | 0.17% | — | Oracle Knowledge Management | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Create, Update, Authoring Flow). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge… | |
| Modificada | Alta (8.8) | 0.21% | — | Wpknowledgebase WP Knowledgebase | 26/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mihai Iova WordPress Knowledge base & Documentation Plugin – WP Knowledgebase plugin <= 1.3.4 versions. | |
| Modificada | Media (6.1) | 0.63% | — | Openknowledgemaps Head Start | 20/9/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visual Project Explorer 1.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'service' parameter in… | |
| Modificada | Media (6.1) | 0.57% | — | Openknowledgemaps Head Start | 13/9/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'file' parameter in 'displayPDF.php'. | |
| Modificada | Alta (7.8) | 0.50% | — | IBM Watson Knowledge Catalog ON Cloud PAK FOR Data | 10/7/2023 | 17/6/2026 | IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782. | |
| Modificada | Media (6.5) | 0.98% | — | IBM Watson Knowledge Catalog ON Cloud PAK FOR Data | 10/7/2023 | 17/6/2026 | IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704. | |
| Modificada | Crítica (9.8) | 0.86% | — | IBM Watson Knowledge Catalog ON Cloud PAK FOR Data | 12/2/2023 | 17/6/2026 | IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 237402. | |
| Modificada | Media (6.1) | 1.0% | — | Public Knowledge Project Open Journal Systems | 4/4/2022 | 17/6/2026 | PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers. | |
| Modificada | Media (6.1) | 6.1% | — | Public Knowledge Project Open Journal Systems | 1/4/2022 | 17/6/2026 | Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header. | |
| Modificada | Media (6.1) | 22% | — | SAP Knowledge Warehouse | 14/12/2021 | 17/6/2026 | A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensitive data. | |
| Modificada | Alta (8.8) | 3.2% | — | SAP Netweaver Knowledge Management XML Forms | 14/9/2021 | 17/6/2026 | SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerability which allows a non-administrative authenticated attacker to craft a malicious XSL stylesheet file containing a script with OS-level commands, copy it into a location to be accessed by the system… | |
| Modificada | Media (6.1) | 2.0% | — | SAP Netweaver Knowledge Management | 10/8/2021 | 17/6/2026 | SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity. | |
| Modificada | Alta (8.2) | 80% | — | Oracle Knowledge Management | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge… | |
| Modificada | Media (6.5) | 1.3% | — | SAP Netweaver Knowledge Management | 9/3/2021 | 17/6/2026 | Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data without verification, leading to insecure deserialization which triggers the attacker’s code, therefore impacting Availability. | |
| Modificada | Media (5.4) | 0.65% | — | SAP Netweaver Knowledge Management | 9/9/2020 | 17/6/2026 | SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked by victim, will execute arbitrary java scripts thus extracting or modifying information otherwise restricted leading to Stored Cross Site Scripting. | |
| Modificada | Media (6.5) | 0.93% | — | SAP Netweaver Knowledge Management | 12/8/2020 | 17/6/2026 | SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and… | |
| Modificada | Crítica (9) | 1.8% | — | SAP Netweaver Knowledge Management | 12/8/2020 | 17/6/2026 | SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in… | |
| Modificada | Media (5.9) | 1.5% | — | Oracle Knowledge | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Information Manager Console). Supported versions that are affected are 8.6.0-8.6.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge. Successful attacks of this… | |
| Modificada | Crítica (9.8) | 2.8% | — | Oracle Knowledge | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Web Applications - InfoCenter). Supported versions that are affected are 8.6.0-8.6.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge. Successful attacks of this… |