Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

4643 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.49%—Oracle Financial Services Behavior Detection Platform18/4/202317/6/2026
Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Application). The supported version that is affected is 8.0.8.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (5.3)0.57%—Juniper Appid Service SigpackJuniper Jdpi-decoder EngineJuniper Junos17/4/202317/6/2026
—
ModificadaMedia (6.1)0.60%—Servicenow17/4/202317/6/2026
There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote attacker to execute arbitrary JavaScript code in the browser-based web console.
ModificadaMedia (6.1)0.64%—Oretnom23 Vehicle Service Management System15/4/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Vehicle Service Management System 1.0. This vulnerability affects unknown code of the file /admin/report/index.php. The manipulation of the argument date_end leads to cross site scripting. The attack can be initiated remotely. The exploit has been…
ModificadaMedia (6.1)0.65%—Vehicle Service Management System Project Vehicle Service Management System15/4/202317/6/2026
A vulnerability classified as problematic has been found in SourceCodester Vehicle Service Management System 1.0. This affects an unknown part of the file /classes/Users.php. The manipulation of the argument id leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been…
ModificadaMedia (6.1)0.64%—Oretnom23 Vehicle Service Management System15/4/202317/6/2026
A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /inc/topBarNav.php. The manipulation of the argument search leads to cross site scripting. The attack may be launched remotely. The…
ModificadaCrítica (9.8)0.84%—Vehicle Service Management System Project Vehicle Service Management System15/4/202317/6/2026
A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit…
ModificadaCrítica (9.8)0.75%—Vehicle Service Management System Project Vehicle Service Management System15/4/202317/6/2026
A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/service_requests/manage_inventory.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The…
ModificadaCrítica (9.8)0.75%—Vehicle Service Management System Project Vehicle Service Management System15/4/202317/6/2026
A vulnerability was found in SourceCodester Vehicle Service Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_category.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has…
AnalizadaCrítica (9.8)0.80%—Oretnom23 Vehicle Service Management System15/4/202317/6/2026
A vulnerability has been found in SourceCodester Vehicle Service Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/mechanics/manage_mechanic.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has…
ModificadaCrítica (9.8)0.75%—Vehicle Service Management System Project Vehicle Service Management System15/4/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Vehicle Service Management System 1.0. This affects an unknown part of the file /classes/Login.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaCrítica (9.8)0.75%—Vehicle Service Management System Project Vehicle Service Management System15/4/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Vehicle Service Management System 1.0. Affected by this issue is some unknown functionality of the file view_service.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has…
ModificadaMedia (6.1)0.30%—Servicenow14/4/202317/6/2026
There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domains when clicking on a URL within a service-now domain.
ModificadaAlta (7.5)0.98%—Microsoft Azure Service Connector11/4/202317/6/2026
Azure Service Connector Security Feature Bypass Vulnerability
ModificadaMedia (5.3)0.45%—SAP Netweaver AS Java FOR Deploy Service11/4/202317/6/2026
SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity enabling an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but…
ModificadaMedia (6.1)0.52%—Pingidentity Self-service Account Manager10/4/202317/6/2026
A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2. Affected by this issue is some unknown functionality of the file src/main/java/com/unboundid/webapp/ssam/SSAMController.java. The manipulation leads to cross site scripting. The attack may be…
ModificadaMedia (6.1)1.1%💥 ExploitServicenow10/4/202317/6/2026
A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various client-side attacks, including, but not…
ModificadaAlta (7.5)78%—Zohocorp Manageengine Adselfservice Plus5/4/202317/6/2026
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaAlta (7.8)0.20%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more…
ModificadaMedia (6.7)0.20%—Cisco Evolved Programmable Network ManagerCisco Identity Services EngineCisco Prime Infrastructure5/4/202317/6/2026
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaMedia (6)0.75%—Cisco Identity Services Engine5/4/202317/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or negatively impact the responsiveness of the web-based…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…