Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
162 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.23% | — | Easebay Resources Login ManagerAI | 18/4/2025 | 17/6/2026 | The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom logo and background URLs in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.6) | 0.15% | — | Intel System Security Report AND System Resources Defense FirmwareAI | 12/2/2025 | 17/6/2026 | Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.21% | — | Intel System Security Report FirmwareAIIntel System Resources Defense FirmwareAI | 12/2/2025 | 17/6/2026 | Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.22% | — | Intel System Security Report AND System Resources Defense FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.16% | — | Intel System Security Report AND System Resources Defense FirmwareAI | 12/2/2025 | 17/6/2026 | Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.6) | 0.16% | — | Intel System Security Report AND System Resources Defense FirmwareAI | 12/2/2025 | 17/6/2026 | Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (8.6) | 0.24% | — | Intel System Security Report AND System Resources Defense FirmwareAI | 12/2/2025 | 17/6/2026 | Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (4.3) | 0.38% | — | Oracle Peoplesoft Enterprise HCM Human Resources | 16/7/2024 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human Resources.… | |
| Modificada | Media (4.3) | 0.45% | — | Oracle Self-service Human Resources | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Workforce Management). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human… | |
| Modificada | Media (5.4) | 0.41% | — | Oracle Peoplesoft Enterprise Human Capital Management Human Resources | 18/4/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Administer Workforce). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Modificada | Media (4.3) | 0.45% | — | Oracle Self-service Human Resources | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Workflow, Approval, Work Force Management). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.5) | 2.1% | 💥 Exploit | Montala Resourcespace | 17/7/2022 | 17/6/2026 | In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value. | |
| Modificada | Media (4.3) | 0.68% | — | Inveniosoftware Invenio-drafts-resources | 6/12/2021 | 17/6/2026 | Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable in a default installation of InvenioRDM.… | |
| Modificada | Media (6.1) | 78% | 💥 Exploit | Montala Resourcespace | 15/11/2021 | 17/6/2026 | ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php via the wordpress_user parameter. If an attacker is able to persuade a victim to visit a crafted URL, malicious JavaScript content may be executed within the context of the victim's… | |
| Modificada | Crítica (9.1) | 75% | — | Montala Resourcespace | 15/11/2021 | 17/6/2026 | A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider and variant parameters in pages/ajax/tiles.php. Attackers can delete configuration or source code files, causing the application to become… | |
| Modificada | Crítica (9.8) | 68% | — | Montala Resourcespace | 15/11/2021 | 17/6/2026 | A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to execute arbitrary SQL commands via the k parameter. This allows attackers to uncover the full contents of the ResourceSpace database, including user session cookies. An… | |
| Modificada | Alta (8.1) | 0.93% | — | Oracle Human Resources | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: People Management). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of… | |
| Modificada | Alta (7.4) | 0.49% | — | Siemens Sinumerik Analyse Mycondition FirmwareSiemens Sinumerik Analyze Myperformance FirmwareSiemens Sinumerik Integrate Client FirmwareSiemens Sinumerik Integrate FOR Production Firmware+6 | 13/7/2021 | 17/6/2026 | A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 <… | |
| Analizada | Alta (8.1) | 1.00% | — | Oracle Human Resources Management System | 22/4/2021 | 24/7/2026 | Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this… | |
| Modificada | Alta (8.1) | 0.93% | — | Oracle Human Resources | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: iRecruitment). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this… | |
| Modificada | Media (5.4) | 0.67% | — | Jenkins Lockable Resources | 23/9/2020 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers to reserve, unreserve, unlock, and reset resources. | |
| Modificada | Media (5.3) | 0.91% | — | Umanni Human Resources | 26/8/2020 | 17/6/2026 | Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 1.6% | — | Umanni Human Resources | 26/8/2020 | 17/6/2026 | Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page. | |
| Analizada | Media (6.1) | 85% | ⚠ Explotación activa💥 Exploit | JqueryDebian LinuxFedoraproject FedoraDrupal+48 | 29/4/2020 | 17/6/2026 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Alta (8.1) | 2.0% | — | Oracle Human Resources | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources.… |