Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.26%—Sysbasics Customize MY Account15/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SysBasics Customize My Account for WooCommerce.This issue affects Customize My Account for WooCommerce: from n/a through 1.8.3.
AnalizadaAlta (7.5)0.70%—Opentext Netiq Privileged Account Manager13/3/202417/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged Account Manager: before 3.7.0.2.
AnalizadaMedia (5.5)0.17%—Samsung Account5/3/202417/6/2026
Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.
AnalizadaAlta (7.5)0.55%—Prestaworld Account Manager3/3/202417/6/2026
An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote attackers to escalate privilege and obtain sensitive information via the uploadLogo() and postProcess methods.
AnalizadaAlta (7.5)0.58%—Prestaworld Account Manager27/2/202417/6/2026
In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.
ModificadaMedia (6.3)0.31%—SAP Bank Account Management13/2/202417/6/2026
SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges with low impact on confidentiality, integrity and availability of the application.
ModificadaAlta (8.8)1.0%—Koalaapps MY Account Page Editor16/1/202417/6/2026
The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE
ModificadaBaja (3.3)0.17%—Amazon Awslabs Sandbox Accounts FOR Events22/12/202317/6/2026
Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially read data from the events table by sending request payloads to the events API, collecting information on planned events, timeframes,…
ModificadaCrítica (9)0.38%—Amazon Awslabs Sandbox Accounts FOR Events22/12/202317/6/2026
"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially claim and access empty AWS accounts by sending request payloads to the account API containing non-existent event ids and self-defined…
ModificadaMedia (5.5)0.26%—Samsung Account WEB Software Development KIT5/12/202317/6/2026
Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensitive information.
ModificadaAlta (7.5)0.76%—Kotchasan Online Accounting System3/12/202317/6/2026
A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4.0 and classified as problematic. This issue affects some unknown processing of the file ckeditor/filemanager/browser/default/image.php. The manipulation of the argument fid with the input ../../../etc/passwd leads to path traversal:…
ModificadaMedia (6.1)0.21%—Phoeniixx Custom MY Account FOR Woocommerce13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in phoeniixx Custom My Account for Woocommerce allows Cross-Site Scripting (XSS).This issue affects Custom My Account for Woocommerce: from n/a through 2.1.
ModificadaMedia (6.5)0.39%—Samsung Account7/11/202317/6/2026
Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
ModificadaMedia (6.5)0.39%—Samsung Account7/11/202317/6/2026
Use of implicit intent for sensitive communication vulnerability in startSignIn in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
ModificadaMedia (6.5)0.39%—Samsung Account7/11/202317/6/2026
Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
ModificadaMedia (6.5)0.39%—Samsung Account7/11/202317/6/2026
Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
ModificadaMedia (6.5)0.39%—Samsung Account7/11/202317/6/2026
Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
ModificadaMedia (6.5)0.39%—Samsung Account7/11/202317/6/2026
Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
ModificadaMedia (5.5)0.19%—Samsung Account7/11/202317/6/2026
Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit intent.
ModificadaMedia (6.1)0.45%—Broadpeak Centralized Accounts Management Auth Agent3/10/202317/6/2026
A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00.19219575_ee9195b0, 01.01.01.30097902_fd999e76, and 00.12.01.9565588_1254b459 allows remote attackers to inject arbitrary web script or HTML via the…
ModificadaMedia (4.3)0.25%—Teknigar Lock User Account11/9/202317/6/2026
The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, which could allow attackers to make logged in admins lock and unlock arbitrary users via a CSRF attack
ModificadaAlta (7.8)0.33%—Canonical AccountsserviceCanonical Ubuntu Linux1/9/202317/6/2026
In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
ModificadaCrítica (9.8)0.62%—Storecommander Quickaccounting25/5/202317/6/2026
In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
ModificadaMedia (6.5)0.47%—Storecommander Scquickaccounting16/5/202317/6/2026
Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for PrestaShop, a guest can access exports from the module which can lead to leak of personnal informations from ps_customer table sush as name / surname / email
ModificadaMedia (6)0.43%—Oracle Banking Virtual Account Management18/4/202317/6/2026
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to…