Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Adaudit Plus | 20/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares. | |
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Adaudit Plus | 20/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option. | |
| Analizada | Alta (8.8) | 2.3% | — | Zohocorp Manageengine Adaudit Plus | 20/5/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data. | |
| Aplazada | Crítica (9.1) | 0.32% | — | Rocket.chat AuditAIFilecachetoolsAI | 18/3/2024 | 17/6/2026 | Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI. | |
| Modificada | Baja (2.6) | 0.30% | — | Oracle Audit Vault AND Database Firewall | 17/2/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks require… | |
| Analizada | Alta (7.5) | 0.43% | — | Oracle Audit Vault AND Database Firewall | 17/2/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks of this… | |
| Analizada | Alta (7.8) | 0.61% | — | Adobe Audition | 15/2/2024 | 17/6/2026 | Audition versions 24.0.3, 23.6.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (8.8) | 5.4% | — | Zohocorp Manageengine Adaudit Plus | 2/2/2024 | 17/6/2026 | ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271. | |
| Modificada | Alta (8.8) | 5.0% | — | Zohocorp Manageengine Adaudit Plus | 2/2/2024 | 17/6/2026 | ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data. | |
| Modificada | Crítica (9.8) | 7.0% | — | Zohocorp Manageengine Adaudit Plus | 2/2/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature. | |
| Modificada | Crítica (9.8) | 7.0% | — | Zohocorp Manageengine Adaudit Plus | 2/2/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option. | |
| Modificada | Baja (2.7) | 2.0% | — | Zohocorp Manageengine Adaudit Plus | 25/1/2024 | 17/6/2026 | Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal. | |
| Modificada | Alta (7.6) | 0.43% | — | Oracle Audit Vault AND Database Firewall | 16/1/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks require… | |
| Modificada | Baja (2.7) | 0.34% | — | Oracle Audit Vault AND Database Firewall | 16/1/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks of this… | |
| Modificada | Baja (3) | 0.33% | — | Oracle Audit Vault AND Database Firewall | 16/1/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. While the vulnerability is… | |
| Modificada | Baja (3.1) | 0.50% | — | Collectiveidea Audited | 4/1/2024 | 14/7/2026 | A race condition exists in Audited 4.0.0 to 5.3.3 that can result in an authenticated user to cause audit log entries to be attributed to another user. | |
| Modificada | Media (5.5) | 0.36% | — | Adobe Audition | 16/11/2023 | 17/6/2026 | Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction… | |
| Modificada | Media (5.5) | 0.36% | — | Adobe Audition | 16/11/2023 | 17/6/2026 | Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction… | |
| Modificada | Media (5.5) | 0.36% | — | Adobe Audition | 16/11/2023 | 17/6/2026 | Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a… | |
| Modificada | Alta (7.8) | 0.38% | — | Adobe Audition | 16/11/2023 | 17/6/2026 | Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.35% | — | Adobe Audition | 16/11/2023 | 17/6/2026 | Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current… | |
| Modificada | Alta (7.8) | 0.35% | — | Adobe Audition | 16/11/2023 | 17/6/2026 | Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current… | |
| Modificada | Alta (7.8) | 0.35% | — | Adobe Audition | 16/11/2023 | 17/6/2026 | Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current… | |
| Modificada | Alta (7.8) | 0.34% | — | Adobe Audition | 16/11/2023 | 17/6/2026 | Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.32% | — | Adobe Audition | 16/11/2023 | 17/6/2026 | Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |