Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)1.2%—Apache Dolphinscheduler12/8/202417/6/2026
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
AplazadaMedia (5.3)0.33%—Jupyter SchedulerAI23/5/202417/6/2026
Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-scheduler` users maybe be exposed, potentially revealing information about projects that a specific user may be working on. This vulnerability has been patched in version(s)…
AplazadaMedia (5.4)0.23%—Revmakx Wpcal.io Easy Meeting SchedulerAI14/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io – Easy Meeting Scheduler: from n/a through 0.9.5.8.
AplazadaMedia (6.6)0.33%💥 PoCQuest Kace Agent FOR WindowsAIQuest KschedulersvcAIQuest Kuser AlertAIQuest RunkbotAI30/4/202417/6/2026
An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges.
AplazadaMedia (4.3)0.20%—Revmakx Wpcal.io Easy Meeting SchedulerAI24/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io – Easy Meeting Scheduler: from n/a through 0.9.5.8.
AnalizadaAlta (8.8)1.4%—Apache Dolphinscheduler23/2/202417/6/2026
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we added one more patch to fix it. This issue affects Apache…
ModificadaAlta (7.5)1.2%💥 PoCApache Dolphinscheduler20/2/202417/6/2026
Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
AnalizadaMedia (6.5)1.3%—Apache Dolphinscheduler20/2/202417/6/2026
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.
AnalizadaAlta (7.3)0.70%—Apache Dolphinscheduler20/2/202417/6/2026
Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. This issue affects Apache DolphinScheduler: before 3.2.0. Users are recommended to upgrade to version 3.2.1, which fixes the issue.
AnalizadaCrítica (9.8)2.3%💥 PoCApache Dolphinscheduler20/2/202417/6/2026
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
ModificadaAlta (8.8)1.4%—Apache Dolphinscheduler30/12/202317/6/2026
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9. Users are recommended to upgrade to version 3.1.9, which fixes the issue.
ModificadaAlta (8.8)1.2%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
ModificadaAlta (7.5)1.1%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
ModificadaMedia (5.4)0.42%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
ModificadaMedia (5.4)0.46%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.
ModificadaMedia (6.5)1.1%—Apache Dolphinscheduler30/11/202317/6/2026
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level because it still requires user login to…
ModificadaAlta (7.5)1.1%—Apache Dolphinscheduler27/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: before 3.2.1. Users are recommended to upgrade to version 3.2.1, which fixes the issue. At the time of disclosure of this advisory, this version has not yet been released. In…
ModificadaAlta (7.5)1.2%—Apache Dolphinscheduler24/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. The information exposed to unauthorized actors may include sensitive data such as database credentials. Users who can't upgrade to the fixed version can also set environment variable…
ModificadaAlta (7.5)0.59%—Phpjabbers Appointment Scheduler10/10/202317/6/2026
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaMedia (6.1)0.38%—Phpjabbers Appointment Scheduler10/10/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (4.8)0.37%—Allmywebneeds Logo Scheduler18/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in All My Web Needs Logo Scheduler plugin <= 1.2.0 versions.
ModificadaMedia (5.4)0.39%—Sos-berlin Jobscheduler13/7/202317/6/2026
JS7 is an Open Source Job Scheduler. Users specify file names when uploading files holding user-generated documentation for JOC Cockpit. Specifically crafted file names allow an XSS attack to inject code that is executed with the browser. Risk of the vulnerability is considered high for branch 1.13 of JobScheduler…
ModificadaMedia (4.3)1.1%—Apache Dolphinscheduler20/4/202317/6/2026
On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attacker could use a socket bytes attack without authentication. This issue has been fixed from version 3.1.2 onwards. For users who use version 3.0.0 to 3.1.1, you can turn off the python-gateway…
ModificadaCrítica (9.1)1.3%—IBM Tivoli Workload Scheduler3/2/202317/6/2026
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233975.
Orbitaley — Vulnerabilidades