Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

267 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.32%—Carmelo Staff Audit System30/6/202517/6/2026
A vulnerability classified as critical was found in code-projects Staff Audit System 1.0. This vulnerability affects unknown code of the file /update_index.php. The manipulation of the argument updateid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may…
AnalizadaMedia (6.5)0.31%—Admin Audit Trail Project Admin Audit Trail11/6/202517/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocation.This issue affects Admin Audit Trail: from 0.0.0 before 1.0.5.
AnalizadaAlta (8.3)1.6%—Zohocorp Manageengine Adaudit Plus9/6/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.
AnalizadaAlta (8.3)1.6%—Zohocorp Manageengine Adaudit Plus9/6/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports.
AnalizadaAlta (8.3)1.6%—Zohocorp Manageengine Adaudit Plus9/6/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports.
AnalizadaAlta (8.3)1.5%—Zohocorp Manageengine Adaudit Plus23/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.
AnalizadaAlta (8.3)37%—Zohocorp Manageengine Adaudit Plus23/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
AnalizadaAlta (8.3)1.7%—Zohocorp Manageengine Adaudit Plus22/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.
AnalizadaAlta (8.3)5.9%—Zohocorp Manageengine Adaudit Plus22/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.
AnalizadaAlta (8.1)1.7%—Zohocorp Manageengine Adaudit Plus14/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.
AplazadaCrítica (9.3)0.50%—Videx Cyberaudit-webAI10/4/202517/6/2026
An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an attacker could create a valid session without any credentials. This vulnerability has been patched in versions later than 9.5 and a patch has been made available to all instances of CyberAudit-Web,…
AplazadaMedia (6)0.36%—Videx Cyberaudit-webAI10/4/202517/6/2026
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAudit-Web, affecting versions prior to 1.1.3. This vulnerability has been patched in versions after 1.1.3. Leaving this vulnerability unpatched could lead to unauthorized access to the underlying…
AplazadaAlta (7.6)0.54%—Generator-jhipster-entity-auditAIJaversAI3/4/202517/6/2026
generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generator-jhipster-entity-audit allows unsafe reflection when having Javers selected as Entity Audit Framework. If an attacker manages to place some malicious classes into the classpath and also has access…
AplazadaAlta (7.1)0.36%—Khanhtruong WP Database AuditAI26/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in khanhtruong WP Database Audit database-audit allows Reflected XSS.This issue affects WP Database Audit: from n/a through <= 1.0.
AplazadaMedia (6.9)2.7%—Bdcom Behavior Management AND Auditing SystemAI21/2/202517/6/2026
A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critical. Affected by this vulnerability is the function log_operate_clear of the file /webui/modules/log/operate.mds. The manipulation of the argument start_code leads to os command injection. The attack…
AplazadaMedia (5.1)0.20%—Kube-audit-restAI29/1/202517/6/2026
kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is fixed in 1.0.16.
AplazadaAlta (7.1)0.32%—Infosoftplugin Order Audit LOG FOR WoocommerceAI13/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in infosoftplugin Order Audit Log for WooCommerce order-audit-log-for-woocommerce allows Reflected XSS.This issue affects Order Audit Log for WooCommerce: from n/a through <= 2.0.
AplazadaMedia (5.3)0.42%—Ideinteractive Content Audit ExporterAI30/11/202417/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ideinteractive Content Audit Exporter content-audit-exporter allows Retrieve Embedded Sensitive Data.This issue affects Content Audit Exporter: from n/a through <= 1.1.
AnalizadaAlta (8.8)3.6%—Zohocorp Manageengine Adaudit Plus18/11/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
AnalizadaMedia (5.5)0.24%—Adobe Audition15/11/202417/6/2026
Audition versions 23.6.9, 24.4.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a…
AnalizadaMedia (5.5)0.23%—Adobe Audition12/11/202417/6/2026
Audition versions 23.6.9, 24.4.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a…
ModificadaAlta (8.8)3.2%—Zohocorp Manageengine Adaudit Plus4/11/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
AnalizadaAlta (8.1)2.5%—Zohocorp Manageengine Adaudit Plus24/10/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.
AnalizadaMedia (5.5)0.24%—Adobe Audition11/9/202417/6/2026
Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a…
AnalizadaAlta (7.8)0.25%—Adobe Audition11/9/202417/6/2026
Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Orbitaley — Vulnerabilidades