Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.8% | — | Ltb-project Ldap Tool BOX Self Service Password | 14/6/2018 | 17/6/2026 | LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string. | |
| Modificada | Media (6.1) | 1.4% | — | Microfocus Self Service Password Reset | 24/3/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Alta (7.4) | 1.2% | — | Lepide Active Directory Self Service | 15/12/2015 | 17/6/2026 | The password reset functionality in Lepide Active Directory Self Service allows remote authenticated users to change arbitrary domain user passwords via a crafted request. | |
| Modificada | Media (6) | 2.3% | — | SAP FI Manager Self-service | 31/7/2014 | 17/6/2026 | SAP FI Manager Self-Service has a hard-coded user name, which makes it easier for remote attackers to obtain access via unspecified vectors. | |
| Modificada | Media (6.2) | 0.77% | — | Oracle Passlogix V-go Self-service Password Reset AND OEM | 7/2/2011 | 16/6/2026 | Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is… | |
| Modificada | Media (6.8) | 5.6% | — | Motive Incorporated Self Service ManagerMotive Incorporated Service Activation Manager | 15/8/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the Motive ActiveEmailTest.EmailData (ActiveUtils EmailData) ActiveX control in ActiveUtils.dll in Motive Service Activation Manager 5.1 and Self Service Manager 5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5) | 1.4% | — | MRO Software Maximo Self Service | 16/5/2005 | 16/6/2026 | MRO Maximo Self Service 4 and 5 stores certain information under the web document root using file extensions that are not processed by Tomcat, which allows remote attackers to obtain sensitive information via a direct request for the file, such as MXServer.properties. |