Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

2298 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.42%—Oracle Timesten In-memory Database21/7/202631/7/2026
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.…
AnalizadaCrítica (9.9)0.43%—Oracle Timesten In-memory Database21/7/202631/7/2026
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.…
AnalizadaMedia (6.5)0.15%—Oracle Timesten In-memory Database21/7/202631/7/2026
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI21/7/202622/7/2026
A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_subjecta.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
AplazadaMedia (5.5)0.43%—Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display SystemAI20/7/202620/7/2026
A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. Impacted is an unknown function of the file /admin/system/structure/updateStructure/deflate/Insecure/Staffshinel Ds.jsp?Shine ID=aaa. The manipulation of the argument Structure_ID results in…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI19/7/202620/7/2026
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_schoolyr.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI19/7/202622/7/2026
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be…
AplazadaBaja (2)0.35%—Sourcecodester Class AND Exam Timetabling SystemAI19/7/202620/7/2026
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /forCYS.php. Such manipulation of the argument course leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and…
AplazadaBaja (2)0.35%—Sourcecodester Class AND Exam Timetabling SystemAI19/7/202622/7/2026
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This manipulation of the argument course causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly…
AplazadaBaja (2)0.35%—Sourcecodester Class AND Exam Timetabling SystemAI18/7/202621/7/2026
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the argument day results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be…
AplazadaBaja (2)0.35%—Sourcecodester Class AND Exam Timetabling SystemAI18/7/202621/7/2026
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /schoolyr.php. The manipulation of the argument sy leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI18/7/202620/7/2026
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_room1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI18/7/202622/7/2026
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
AnalizadaAlta (7.5)0.74%—Linuxfoundation Sigstore Timestamp Authority17/7/202630/7/2026
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote…
AplazadaBaja (2.1)0.49%—Sourcecodester Class AND Exam Timetabling SystemAI14/7/202614/7/2026
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /exam.php. Such manipulation of the argument day leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available…
AplazadaAlta (8.7)0.44%—Sesame TimeAI14/7/202615/7/2026
A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time web application and its REST v3 API. The flaw lies in the fact that the system uses the session identifier (USID) as the sole validation mechanism, without verifying whether that identifier…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI13/7/202614/7/2026
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/2.php. This affects an unknown function of the file /edit_exam2.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and…
AplazadaBaja (2.1)0.47%—Sourcecodester Class AND Exam Timetabling SystemAI13/7/202615/7/2026
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /subject.php. Such manipulation of the argument subject leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and…
AplazadaBaja (2.1)0.47%—Sourcecodester Class AND Exam Timetabling SystemAI13/7/202614/7/2026
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /forsubject.php. This manipulation of the argument subject causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed…
AplazadaMedia (6.5)0.22%—Spacetime AD InserterAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spacetime Ad Inserter ad-inserter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ad Inserter: from n/a through <= 2.8.11.
AplazadaBaja (2.1)0.35%—LeantimeAI12/7/202613/7/2026
A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure…
AplazadaBaja (2.1)0.35%—LeantimeAI12/7/202615/7/2026
A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.…
AplazadaAlta (8.7)0.62%—Openplc RuntimeAI10/7/202613/7/2026
OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database field and later uses this value as the destination path for an uploaded file without…
AplazadaMedia (6.5)0.47%—Wptimecapsule Backup AND Staging BY WP Time CapsuleAI9/7/20269/7/2026
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract download the…
AplazadaMedia (6.5)0.17%—Bytecodealliance WasmtimeAI8/7/202610/7/2026
Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as…
Orbitaley — Vulnerabilidades