Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.26% | — | Sysbasics Customize MY Account | 15/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SysBasics Customize My Account for WooCommerce.This issue affects Customize My Account for WooCommerce: from n/a through 1.8.3. | |
| Analizada | Alta (7.5) | 0.70% | — | Opentext Netiq Privileged Account Manager | 13/3/2024 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged Account Manager: before 3.7.0.2. | |
| Analizada | Media (5.5) | 0.17% | — | Samsung Account | 5/3/2024 | 17/6/2026 | Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data. | |
| Analizada | Alta (7.5) | 0.55% | — | Prestaworld Account Manager | 3/3/2024 | 17/6/2026 | An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote attackers to escalate privilege and obtain sensitive information via the uploadLogo() and postProcess methods. | |
| Analizada | Alta (7.5) | 0.58% | — | Prestaworld Account Manager | 27/2/2024 | 17/6/2026 | In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. | |
| Modificada | Media (6.3) | 0.31% | — | SAP Bank Account Management | 13/2/2024 | 17/6/2026 | SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges with low impact on confidentiality, integrity and availability of the application. | |
| Modificada | Alta (8.8) | 1.0% | — | Koalaapps MY Account Page Editor | 16/1/2024 | 17/6/2026 | The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE | |
| Modificada | Baja (3.3) | 0.17% | — | Amazon Awslabs Sandbox Accounts FOR Events | 22/12/2023 | 17/6/2026 | Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially read data from the events table by sending request payloads to the events API, collecting information on planned events, timeframes,… | |
| Modificada | Crítica (9) | 0.38% | — | Amazon Awslabs Sandbox Accounts FOR Events | 22/12/2023 | 17/6/2026 | "Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially claim and access empty AWS accounts by sending request payloads to the account API containing non-existent event ids and self-defined… | |
| Modificada | Media (5.5) | 0.26% | — | Samsung Account WEB Software Development KIT | 5/12/2023 | 17/6/2026 | Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensitive information. | |
| Modificada | Alta (7.5) | 0.76% | — | Kotchasan Online Accounting System | 3/12/2023 | 17/6/2026 | A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4.0 and classified as problematic. This issue affects some unknown processing of the file ckeditor/filemanager/browser/default/image.php. The manipulation of the argument fid with the input ../../../etc/passwd leads to path traversal:… | |
| Modificada | Media (6.1) | 0.21% | — | Phoeniixx Custom MY Account FOR Woocommerce | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in phoeniixx Custom My Account for Woocommerce allows Cross-Site Scripting (XSS).This issue affects Custom My Account for Woocommerce: from n/a through 2.1. | |
| Modificada | Media (6.5) | 0.39% | — | Samsung Account | 7/11/2023 | 17/6/2026 | Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. | |
| Modificada | Media (6.5) | 0.39% | — | Samsung Account | 7/11/2023 | 17/6/2026 | Use of implicit intent for sensitive communication vulnerability in startSignIn in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. | |
| Modificada | Media (6.5) | 0.39% | — | Samsung Account | 7/11/2023 | 17/6/2026 | Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. | |
| Modificada | Media (6.5) | 0.39% | — | Samsung Account | 7/11/2023 | 17/6/2026 | Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. | |
| Modificada | Media (6.5) | 0.39% | — | Samsung Account | 7/11/2023 | 17/6/2026 | Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. | |
| Modificada | Media (6.5) | 0.39% | — | Samsung Account | 7/11/2023 | 17/6/2026 | Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. | |
| Modificada | Media (5.5) | 0.19% | — | Samsung Account | 7/11/2023 | 17/6/2026 | Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit intent. | |
| Modificada | Media (6.1) | 0.45% | — | Broadpeak Centralized Accounts Management Auth Agent | 3/10/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00.19219575_ee9195b0, 01.01.01.30097902_fd999e76, and 00.12.01.9565588_1254b459 allows remote attackers to inject arbitrary web script or HTML via the… | |
| Modificada | Media (4.3) | 0.25% | — | Teknigar Lock User Account | 11/9/2023 | 17/6/2026 | The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, which could allow attackers to make logged in admins lock and unlock arbitrary users via a CSRF attack | |
| Modificada | Alta (7.8) | 0.33% | — | Canonical AccountsserviceCanonical Ubuntu Linux | 1/9/2023 | 17/6/2026 | In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process. | |
| Modificada | Crítica (9.8) | 0.62% | — | Storecommander Quickaccounting | 25/5/2023 | 17/6/2026 | In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection. | |
| Modificada | Media (6.5) | 0.47% | — | Storecommander Scquickaccounting | 16/5/2023 | 17/6/2026 | Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for PrestaShop, a guest can access exports from the module which can lead to leak of personnal informations from ps_customer table sush as name / surname / email | |
| Modificada | Media (6) | 0.43% | — | Oracle Banking Virtual Account Management | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to… |