Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

22.754 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.41%—Oracle Hyperion Financial Management18/8/202624/8/2026
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful…
AnalizadaMedia (6)0.18%—Oracle Hyperion Financial Management18/8/202621/9/2026
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to…
Pendiente de análisisAlta (7.3)0.17%—Dell AppsyncAIDell Metro NodeAIDell UCC EdgeAIDell VxrailAI+518/8/202620/8/2026
Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4…
Pendiente de análisisAlta (8.7)0.27%—Managed-serviceaccountAIKubernetes Addon-managerAI18/8/202620/8/2026
A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation…
Pendiente de análisisMedia (4.4)0.35%—Submariner-operatorAIRedhat Advanced Cluster Management FOR KubernetesAI18/8/20263/9/2026
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker…
Pendiente de análisisMedia (6.7)0.47%—Otalio Ship Property Management SystemAI18/8/202629/9/2026
Valores almacenados sin escapar en la página de seguridad de la aplicación en versiones de Otalio Ship Property Management System anteriores a la 2.22.0 permiten a atacantes autenticados escalar privilegios mediante cross-site scripting persistente
Pendiente de análisisAlta (8.1)0.26%—Otalio Ship Property Management SystemAI18/8/202629/9/2026
Falta de validación de firma en JSON Web Tokens en el Sistema de Gestión de Propiedades Otalio Ship versiones anteriores a la 2.22.0 permite a atacantes autenticados escalar privilegios mediante la manipulación de JWTs.
Pendiente de análisisMedia (5.5)0.19%—Redhat Advanced Cluster Management FOR KubernetesAI18/8/20265/9/2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially…
Pendiente de análisisMedia (5.5)0.11%—Redhat Advanced Cluster Management FOR KubernetesAI18/8/20265/9/2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive,…
AplazadaAlta (7.1)0.25%—Wpaffiliatemanager Affiliates ManagerAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.
AplazadaCrítica (9.3)0.40%—Wpaffiliatemanager Affiliates ManagerAI18/8/202620/8/2026
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
AplazadaAlta (7.1)0.29%—Wpexperts License Manager FOR WoocommerceAI18/8/202620/8/2026
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
AplazadaAlta (7.1)0.25%—Wpdownloadmanager Wpdm Premium PackagesAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
Pendiente de análisisAlta (8.8)0.81%—Redhat Advanced Cluster Management FOR KubernetesAIRedhat Governance Policy Addon ControllerAI18/8/202627/8/2026
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with…
AplazadaMedia (5.5)0.43%—Code-projects Task Management SystemAI18/8/202620/8/2026
A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of the file /index.php of the component Login Form. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit…
AplazadaMedia (5.3)0.22%—Sourcecodester Onlne Examination & Learning Management SystemAI18/8/202620/8/2026
A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.
AplazadaMedia (5.5)0.43%—Phpgurukul Complaint Management SystemAI18/8/202620/8/2026
A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/check_availability.php. This manipulation of the argument email causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI18/8/202620/8/2026
A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executing a manipulation of the argument delid can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI18/8/202620/8/2026
A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performing a manipulation of the argument delid results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI18/8/202620/8/2026
A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php. Such manipulation of the argument delid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be…
AplazadaMedia (5.5)0.43%—Sourcecodester PET Grooming Management SoftwareAI17/8/202620/8/2026
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the argument barcode causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Pendiente de análisisCrítica (9.9)0.49%—Open Cluster Management Managedcluster Import ControllerAI17/8/202629/9/2026
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to…
Pendiente de análisisAlta (7.3)0.13%—Beyondtrust Endpoint Privilege ManagementAI17/8/202618/8/2026
A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input processed by the component may result in memory being accessed outside its intended bounds.
AplazadaAlta (8.7)0.94%—2100 Technology Official Document Management SystemAI17/8/202626/8/2026
Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI17/8/202620/8/2026
A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewprescriptionrecord.php. The manipulation of the argument delid results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.