Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

96 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.25%—SAP Shared Service Framework13/8/202417/6/2026
SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application
AnalizadaMedia (6.5)0.32%—SAP Shared Service Framework13/8/202417/6/2026
SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On successful exploitation, an attacker can cause a high impact on confidentiality of the application.
AnalizadaMedia (5.4)0.27%—Oracle Peoplesoft Enterprise HCM Shared Components16/7/202417/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared Components.…
AplazadaCrítica (9.8)0.68%—Agreejs SharedAI1/7/202417/6/2026
agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
AplazadaMedia (5.3)0.39%—Anssi Laitila Shared FilesAI23/4/202417/6/2026
Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.16.
AnalizadaAlta (8.1)5.0%—Microsoft Azure C Shared Utility26/3/202417/6/2026
The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocation or heap buffer overflow due to vulnerabilities in…
ModificadaMedia (6.1)0.42%—Tammersoft Shared Files16/10/202317/6/2026
The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.
ModificadaCrítica (9.8)4.4%—Apache Maven Shared UtilsDebian Linux23/5/202217/6/2026
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
ModificadaMedia (4.8)0.67%—Tammersoft Shared Files17/11/202117/6/2026
The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (4.8)0.64%—Tammersoft Shared Files18/10/202117/6/2026
The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.
ModificadaMedia (6.5)0.90%—Oracle Peoplesoft Enterprise HCM Shared Components21/7/202117/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared…
ModificadaCrítica (9.8)2.1%—Amazon AWS SDK FOR JavasciptAmazon AWS Shared Configuration File Loader19/1/202117/6/2026
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the…
ModificadaMedia (4.3)0.76%—Jenkins Shared Objects8/10/202017/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to configure shared objects.
ModificadaMedia (6.1)1.4%—Oracle Peoplesoft Enterprise Human Capital Management Shared Components19/4/201817/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Shared Components component of Oracle PeopleSoft Products (subcomponent: Notepad). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared…
ModificadaAlta (7.2)0.84%—IBM Monitoring Agent FOR Unix LogsIBM Monitoring Server (ms) AND Shared Libraries (ax)29/8/201416/6/2026
Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM) on UNIX allow…
ModificadaMedia (5.8)1.1%—TIM Nelson Shared Sign-on9/10/200916/6/2026
Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack web sessions via unspecified vectors.
ModificadaMedia (6.8)0.60%—TIM Nelson Shared Sign-on9/10/200916/6/2026
Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.
ModificadaMedia (6.8)1.1%—Shatm Sharedlog18/3/200916/6/2026
PHP remote file inclusion vulnerability in slideshow_uploadvideo.content.php in SharedLog, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[root_dir] parameter.
ModificadaMedia (4.3)1.5%—4shared Starsgames Control Panel27/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the st parameter.
ModificadaMedia (6.8)30%—HP Openview OperationsHP Shared Trace Service9/8/200716/6/2026
Multiple stack-based buffer overflows in the Shared Trace Service (OVTrace) service for HP OpenView Operations A.07.50 for Windows, and possibly earlier versions, allow remote attackers to execute arbitrary code via certain crafted requests.
ModificadaMedia (6.8)3.4%—Evolution Shared Memo21/3/200716/6/2026
Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code via format specifiers in the categories of a crafted shared memo.