Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.25% | — | SAP Shared Service Framework | 13/8/2024 | 17/6/2026 | SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application | |
| Analizada | Media (6.5) | 0.32% | — | SAP Shared Service Framework | 13/8/2024 | 17/6/2026 | SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On successful exploitation, an attacker can cause a high impact on confidentiality of the application. | |
| Analizada | Media (5.4) | 0.27% | — | Oracle Peoplesoft Enterprise HCM Shared Components | 16/7/2024 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared Components.… | |
| Aplazada | Crítica (9.8) | 0.68% | — | Agreejs SharedAI | 1/7/2024 | 17/6/2026 | agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Aplazada | Media (5.3) | 0.39% | — | Anssi Laitila Shared FilesAI | 23/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.16. | |
| Analizada | Alta (8.1) | 5.0% | — | Microsoft Azure C Shared Utility | 26/3/2024 | 17/6/2026 | The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocation or heap buffer overflow due to vulnerabilities in… | |
| Modificada | Media (6.1) | 0.42% | — | Tammersoft Shared Files | 16/10/2023 | 17/6/2026 | The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts. | |
| Modificada | Crítica (9.8) | 4.4% | — | Apache Maven Shared UtilsDebian Linux | 23/5/2022 | 17/6/2026 | In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. | |
| Modificada | Media (4.8) | 0.67% | — | Tammersoft Shared Files | 17/11/2021 | 17/6/2026 | The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.8) | 0.64% | — | Tammersoft Shared Files | 18/10/2021 | 17/6/2026 | The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues. | |
| Modificada | Media (6.5) | 0.90% | — | Oracle Peoplesoft Enterprise HCM Shared Components | 21/7/2021 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared… | |
| Modificada | Crítica (9.8) | 2.1% | — | Amazon AWS SDK FOR JavasciptAmazon AWS Shared Configuration File Loader | 19/1/2021 | 17/6/2026 | This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the… | |
| Modificada | Media (4.3) | 0.76% | — | Jenkins Shared Objects | 8/10/2020 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to configure shared objects. | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Peoplesoft Enterprise Human Capital Management Shared Components | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Shared Components component of Oracle PeopleSoft Products (subcomponent: Notepad). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared… | |
| Modificada | Alta (7.2) | 0.84% | — | IBM Monitoring Agent FOR Unix LogsIBM Monitoring Server (ms) AND Shared Libraries (ax) | 29/8/2014 | 16/6/2026 | Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM) on UNIX allow… | |
| Modificada | Media (5.8) | 1.1% | — | TIM Nelson Shared Sign-on | 9/10/2009 | 16/6/2026 | Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (6.8) | 0.60% | — | TIM Nelson Shared Sign-on | 9/10/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users via unknown vectors. | |
| Modificada | Media (6.8) | 1.1% | — | Shatm Sharedlog | 18/3/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in slideshow_uploadvideo.content.php in SharedLog, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[root_dir] parameter. | |
| Modificada | Media (4.3) | 1.5% | — | 4shared Starsgames Control Panel | 27/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the st parameter. | |
| Modificada | Media (6.8) | 30% | — | HP Openview OperationsHP Shared Trace Service | 9/8/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the Shared Trace Service (OVTrace) service for HP OpenView Operations A.07.50 for Windows, and possibly earlier versions, allow remote attackers to execute arbitrary code via certain crafted requests. | |
| Modificada | Media (6.8) | 3.4% | — | Evolution Shared Memo | 21/3/2007 | 16/6/2026 | Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code via format specifiers in the categories of a crafted shared memo. |