Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.4% | — | IBM Tivoli Workload Scheduler | 3/2/2023 | 17/6/2026 | IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226328. | |
| Modificada | Crítica (9.8) | 2.5% | — | Apache Dolphinscheduler | 4/1/2023 | 17/6/2026 | Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by authenticated users which can login to DS. | |
| Modificada | Media (6.1) | 0.54% | — | Innologi Appointment Scheduler | 4/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in innologi appointments Extension up to 2.0.5 on TYPO3. This affects an unknown part of the component Appointment Handler. The manipulation of the argument formfield leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading… | |
| Modificada | Media (6.1) | 0.63% | — | Resque-scheduler Project Resque-scheduler | 13/12/2022 | 9/7/2026 | Resque Scheduler version 1.27.4 is vulnerable to Cross-site scripting (XSS). A remote attacker could inject javascript code to the "{schedule_job}" or "args" parameter in /resque/delayed/jobs/{schedule_job}?args={args_id} to execute javascript at client side. | |
| Modificada | Alta (7.5) | 1.3% | — | Apache Dolphinscheduler | 24/11/2022 | 17/6/2026 | When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher. | |
| Modificada | Crítica (9.8) | 2.8% | — | Apache Dolphinscheduler | 23/11/2022 | 17/6/2026 | Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher | |
| Modificada | Media (6.5) | 1.6% | 💥 PoC | Apache Dolphinscheduler | 1/11/2022 | 17/6/2026 | When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher | |
| Modificada | Media (6.1) | 0.51% | — | Train Scheduler APP Project Train Scheduler APP | 1/11/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /admin/add-fee.php of Train Scheduler App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter. | |
| Modificada | Crítica (9.1) | 1.2% | — | Train Scheduler APP Project Train Scheduler APP | 31/10/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /train_scheduler_app/?action=delete. The manipulation of the argument id leads to improper control of resource identifiers. The attack may be launched… | |
| Modificada | Media (6.5) | 1.6% | 💥 PoC | Apache Dolphinscheduler | 28/10/2022 | 17/6/2026 | Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher. | |
| Modificada | Media (5.4) | 0.49% | — | Train Scheduler APP Project Train Scheduler APP | 27/10/2022 | 9/7/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Train Code, Train Name, and Destination text fields. | |
| Modificada | Alta (8.8) | 0.43% | — | Backup Scheduler Project Backup Scheduler | 23/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability Backup Scheduler plugin <= 1.5.13 at WordPress. | |
| Modificada | Alta (7.1) | 0.19% | — | IBM Workload Scheduler | 10/8/2022 | 17/6/2026 | IBM Workload Scheduler 9.4 and 9.5 could allow a local user to overwrite key system files which would cause the system to crash. IBM X-Force ID: 221187. | |
| Modificada | Media (5.4) | 0.69% | — | Ttpsc THE Scheduler | 13/7/2022 | 17/6/2026 | The Transition Scheduler add-on 6.5.0 for Atlassian Jira is prone to stored XSS via the project name to the creation function. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Modificada | Alta (7.5) | 2.0% | — | Apache Dolphinscheduler | 30/3/2022 | 17/6/2026 | Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher. | |
| Modificada | Media (6.1) | 0.80% | — | Myceliumdesign Conference Scheduler | 28/3/2022 | 17/6/2026 | The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Media (6.1) | 1.0% | — | Online Covid Vaccination Scheduler System Project Online Covid Vaccination Scheduler System | 24/1/2022 | 17/6/2026 | Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid Vaccination Scheduler System v1 by oretnom23, allows attackers to execute arbitrary code via the lid parameter to /scheduler/addSchedule.php. | |
| Modificada | Crítica (9.8) | 1.3% | — | Patient Appointment Scheduler System Project Patient Appointment Scheduler System | 24/1/2022 | 17/6/2026 | SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Apache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+51 | 14/12/2021 | 17/6/2026 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (8.8) | 1.9% | — | Apache Dolphinscheduler | 1/11/2021 | 17/6/2026 | In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password) | |
| Modificada | Alta (8.1) | 1.6% | — | Online Covid Vaccination Scheduler System Project Online Covid Vaccination Scheduler System | 27/10/2021 | 17/6/2026 | An SQL Injection vulnerability exists in Sourcecodester Online Covid Vaccination Scheduler System 1.0 via the username in lognin.php . | |
| Modificada | Crítica (10) | 3.8% | — | Siemens Desigo CCSiemens Siveillance Control PROSiemens Gma-managerSiemens Operation Scheduler+1 | 14/9/2021 | 17/6/2026 | A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance Control (All versions with OIS running on Debian 9 or earlier),… | |
| Modificada | Media (5.3) | 0.25% | — | IBM Tivoli Workload Scheduler | 9/8/2021 | 17/6/2026 | IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 194599. |