Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
524 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.21% | — | Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY Manager+2 | 23/6/2025 | 17/6/2026 | An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a specific bypass method to retrieve versioned files without proper… | |
| Analizada | Media (5.2) | 0.53% | — | Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY Manager+2 | 2/6/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. A malicious actor can inject a specially crafted payload into the request, causing the browser to execute arbitrary… | |
| Analizada | Media (6.5) | 0.22% | — | Wso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAMWso2 Open Banking KM | 2/6/2025 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and external resources available through the network or filesystem.… | |
| Analizada | Media (4.3) | 0.66% | 💥 Exploit | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+2 | 30/5/2025 | 17/6/2026 | An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper authorization.… | |
| Modificada | Media (5.4) | 0.71% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+2 | 30/5/2025 | 17/6/2026 | Exploiting this vulnerability allows malicious actors to assign higher privileges to self-registered users, bypassing intended access control mechanisms. | |
| Analizada | Crítica (9.8) | 0.72% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+2 | 22/5/2025 | 17/6/2026 | An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exploit this vulnerability to reset the password of any user account, leading to a complete account takeover, including accounts with elevated… | |
| Analizada | Media (4.8) | 0.40% | — | Code-projects Simple Banking System | 10/5/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the component Sign In. The manipulation of the argument password2 leads to buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the… | |
| Analizada | Media (4.8) | 0.31% | — | Fabian ATM Banking | 28/4/2025 | 17/6/2026 | A vulnerability was found in code-projects ATM Banking 1.0. It has been classified as critical. Affected is the function moneyDeposit/moneyWithdraw. The manipulation leads to business logic errors. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.1) | 0.30% | 💥 PoC | Codeastro Internet Banking System | 17/4/2025 | 17/6/2026 | Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php. | |
| Analizada | Alta (8.8) | 0.88% | 💥 PoC | Codeastro Internet Banking System | 10/4/2025 | 17/6/2026 | A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php. | |
| Analizada | Media (4.8) | 0.27% | 💥 PoC | Codeastro Internet Banking System | 9/4/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0. | |
| Analizada | Crítica (9.8) | 0.62% | — | Martmbithi Ibanking | 20/3/2025 | 17/6/2026 | An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Media (4.8) | 0.23% | — | Martmbithi Ibanking | 20/3/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter. | |
| Analizada | Alta (7.3) | 0.45% | 💥 PoC | Codeastro Internet Banking System | 22/1/2025 | 17/6/2026 | A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This… | |
| Aplazada | Alta (8.8) | 0.52% | — | Polaris FT Intellect Core BankingAI | 8/1/2025 | 17/6/2026 | An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGController is mishandled before being used in SQL queries, allowing SQL injection in an authenticated session. | |
| Analizada | Alta (7.1) | 0.36% | — | Oracle Banking Liquidity Management | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Liquidity… | |
| Analizada | Alta (7.1) | 0.36% | — | Oracle Banking Liquidity Management | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Liquidity… | |
| Modificada | Media (5.3) | 0.32% | — | Oracle Banking Liquidity Management | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.7.0.6.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking… | |
| Modificada | Media (6.9) | 0.56% | — | Itsourcecode Banking Management System Project IN PHP | 20/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Banking Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin_class.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 22/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_client_signup.php. The manipulation of the argument Client Full Name with the input <meta http-equiv="refresh" content="0; url=https://vuldb.com" /> leads to open… | |
| Modificada | Media (5.4) | 0.56% | — | Martinmbithi Internet Banking System | 22/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. Affected by this vulnerability is an unknown functionality of the file pages_client_signup.php. The manipulation of the argument Client Full Name leads to cross site scripting. The attack can be launched remotely. The exploit… | |
| Modificada | Media (5.4) | 0.50% | — | Codeastro Simple Banking System | 11/1/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in CodeAstro Simple Banking System 1.0. This affects an unknown part of the file createuser.php of the component Create a User Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.74% | — | Codeastro Internet Banking System | 2/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of the file pages_account.php of the component Profile Picture Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The… | |
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 23/10/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issue affects some unknown processing of the file pages_view_client.php. The manipulation of the argument acc_name with the input Johnnie Reyes'"()&%<zzz><ScRiPt >alert(5646)</ScRiPt> leads to cross site… | |
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 23/10/2023 | 17/6/2026 | A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects unknown code of the file pages_deposit_money.php. The manipulation of the argument account_number with the input 421873905--><ScRiPt%20>alert(9523)</ScRiPt><!-- leads to cross site scripting. The… |