Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

3977 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.2)0.71%—SafelineAI16/9/202623/9/2026
SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp can regenerate the secret and forge valid administrator session cookies to gain…
AplazadaBaja (1.9)0.38%—Sourcecodester Online Food Ordering SystemAI16/9/202622/9/2026
A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to…
Pendiente de análisisMedia (4.2)0.23%—Jenkins Pipeline Groovy LibrariesAIJenkins PipelineAI16/9/202618/9/2026
Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the library, resulting in a path traversal…
Pendiente de análisisBaja (3.1)0.22%—Jenkins Pipeline Multibranch PluginAI16/9/202618/9/2026
Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
Pendiente de análisisCrítica (9.1)0.20%—Delinea Secret ServerAI15/9/202618/9/2026
An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.
Pendiente de análisisAlta (7.5)0.39%—Oracle Sales OfflineAIOracle E-business SuiteAI15/9/202616/9/2026
Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of…
Pendiente de análisisAlta (7.7)0.34%—Oracle Sales OfflineAIOracle E-business SuiteAI15/9/202616/9/2026
Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. While the…
AplazadaAlta (8.8)0.42%—Oracle Sales OnlineAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online. Successful attacks of…
AplazadaAlta (8.5)0.29%—Oracle Sales OnlineAIOracle E-business SuiteAI15/9/202621/9/2026
Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: OSO Other). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online. While the vulnerability is in…
AplazadaAlta (7.6)0.15%—Oracle Sales OnlineAIOracle E-business SuiteAI15/9/202621/9/2026
Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online. Successful attacks…
Pendiente de análisisMedia (6.5)0.59%—Pipelines-as-codeAITektonAI15/9/202630/9/2026
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the repository that triggered the event when the App is installed across multiple…
Pendiente de análisisAlta (8.2)0.27%—Cd.foundation Pipelines AS CodeAI15/9/202630/9/2026
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature…
AplazadaBaja (2.1)0.37%—Sourcecodester Online Faculty Clearance SystemAI15/9/202617/9/2026
A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture Upload. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Faculty Clearance SystemAI15/9/202615/9/2026
A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Faculty Clearance SystemAI15/9/202615/9/2026
A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injection. It is possible to launch the attack remotely. The exploit has been made…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Faculty Clearance SystemAI15/9/202616/9/2026
A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AplazadaMedia (5.5)0.52%—Subhajitkhan Online-clinic-management-systemAI15/9/202615/9/2026
A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of the argument adminmail can lead to authorization bypass. The attack may be…
AplazadaMedia (5.5)0.41%—Sourcecodester Katojkalemba Online Food Ordering SystemAI15/9/202615/9/2026
A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be…
AplazadaMedia (5.5)0.41%—Sourcecodester Katojkalemba Online Food Ordering SystemAI15/9/202616/9/2026
A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released…
AplazadaMedia (5.5)0.43%—Subhajitkhan Online-clinic-management-systemAI14/9/202615/9/2026
A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd can lead to sql injection. The attack can be executed remotely. The exploit has been…
AplazadaMedia (5.5)0.43%—Subhajitkhan Online-clinic-management-systemAI14/9/202614/9/2026
A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of the argument searchtext results in sql injection. The attack may be initiated remotely. The…
AplazadaBaja (2.1)0.32%—Gongshengyue OnlinebooksAI13/9/202616/9/2026
A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection. The attack may…
AplazadaMedia (6.4)0.36%—Bold-themes Bold Timeline LiteAI11/9/202611/9/2026
The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+48/9/202617/9/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+48/9/202617/9/2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.