Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6)0.43%—Oracle Banking Virtual Account Management18/4/202317/6/2026
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to…
ModificadaMedia (6.1)0.58%—Oracle Banking Virtual Account Management18/4/202317/6/2026
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: SMS Module). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (6.1)0.55%—Oracle Banking Virtual Account Management18/4/202317/6/2026
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Routing Hub). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (5.3)0.40%—Oracle Banking Virtual Account Management18/4/202317/6/2026
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to…
ModificadaMedia (5.3)0.40%—Oracle Banking Virtual Account Management18/4/202317/6/2026
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Internal Tfr Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to…
ModificadaMedia (6.1)0.52%—Pingidentity Self-service Account Manager10/4/202317/6/2026
A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2. Affected by this issue is some unknown functionality of the file src/main/java/com/unboundid/webapp/ssam/SSAMController.java. The manipulation leads to cross site scripting. The attack may be…
ModificadaMedia (4.3)0.40%—Cloudfoundry User Account AND Authentication28/3/202317/6/2026
This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an external identity provider is linked to the UAA, a refresh token is issued to a client on behalf of a user from that identity provider, the administrator of the UAA deactivates the identity provider…
ModificadaMedia (6.1)0.56%—Monitoring OF Students Cyber Accounts System Project Monitoring OF Students Cyber Accounts System18/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. Affected by this issue is some unknown functionality of the file modules/balance/index.php?view=balancelist of the component POST Parameter Handler. The manipulation of the argument…
ModificadaCrítica (9.8)0.74%—Monitoring OF Students Cyber Accounts System Project Monitoring OF Students Cyber Accounts System18/3/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument un leads to sql injection. The attack can be…
ModificadaMedia (5.7)0.51%—SAP Bank Account Management10/1/202317/6/2026
In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directly in the URL. They might get captured in log files, bookmarks, and so on disclosing sensitive data of the application.
ModificadaMedia (4.4)0.16%—Samsung Account7/10/202217/6/2026
Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.
ModificadaMedia (5.5)0.19%—Samsung Account7/10/202217/6/2026
Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.
ModificadaMedia (4.7)0.40%—Samsung Account7/10/202217/6/2026
Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content providers without permission.
ModificadaAlta (7.5)0.89%—Ethereum Eth-account22/8/202217/6/2026
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an attacker is able to supply arbitrary input to the encode_structured_data method
ModificadaMedia (5.3)1.3%—Ldap-account-manager Ldap Account ManagerDebian Linux27/6/202217/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the user name field at login could be used to enumerate LDAP data. This is only the case for LDAP search configuration. This issue has been fixed in version 8.0.
ModificadaAlta (7.8)0.44%—Ldap-account-manager Ldap Account ManagerDebian Linux27/6/202217/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows interpretation of .php (and .php5/.php4/.phpt/etc) files. An attacker capable of writing files under…
ModificadaAlta (8.8)2.3%—Ldap-account-manager Ldap Account ManagerDebian Linux27/6/202217/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the…
ModificadaMedia (6.1)0.27%—Ldap-account-manager Ldap Account ManagerDebian Linux27/6/202217/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the session files include the LDAP user name and password in clear text if the PHP OpenSSL extension is not installed or encryption is disabled by configuration.…
ModificadaAlta (8.1)2.5%—Ldap-account-manager Ldap Account ManagerDebian Linux27/6/202217/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 There are cases where LAM instantiates objects from arbitrary classes. An attacker can inject the first constructor argument. This can lead to code execution if…
ModificadaMedia (6.5)0.66%—SAP ERP Financial AccountingSAP ERP Localization FOR CEE CountriesSAP S/4hana14/6/202217/6/2026
Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.
ModificadaMedia (5.3)0.41%—Samsung Account7/6/202217/6/2026
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
ModificadaMedia (4.3)0.40%—Samsung Account7/6/202217/6/2026
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.
ModificadaMedia (5.3)0.55%—Samsung Account7/6/202217/6/2026
Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.
ModificadaMedia (5.3)0.41%—Samsung Account7/6/202217/6/2026
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
ModificadaAlta (7.5)0.45%—Samsung Account7/6/202217/6/2026
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.
Orbitaley — Vulnerabilidades