Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

1090 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.39%—Oracle Peoplesoft Enterprise PT Peopletools17/6/202624/6/2026
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT…
AnalizadaCrítica (9.8)0.51%—Oracle Peoplesoft Enterprise PT Peopletools17/6/202624/6/2026
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT…
AnalizadaAlta (8.1)0.39%—Oracle Peoplesoft Enterprise PT Peopletools17/6/202624/6/2026
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Application Server). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT…
AnalizadaAlta (8.2)0.35%—Oracle Peoplesoft Enterprise PT Peopletools17/6/202624/6/2026
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT…
AnalizadaAlta (8.4)0.19%—Oracle Peoplesoft Enterprise PT Peopletools17/6/202624/6/2026
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PT PeopleTools…
AnalizadaAlta (8.7)0.34%—Oracle Peoplesoft Enterprise PT Peopletools17/6/202624/6/2026
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. While…
AplazadaAlta (8.5)0.36%—Codepeople WP Time Slots Booking FormAI15/6/202617/6/2026
Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.
AplazadaAlta (7.1)0.25%💥 PoCCodepeople WP Time Slots Booking FormAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions.
AplazadaMedia (5.4)0.27%—Codepeople Form Builder CPAI15/6/202621/7/2026
The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against any visitor of a page…
AplazadaMedia (4.3)0.10%—Magepeople WpeventlyAI11/6/202623/7/2026
Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This issue affects WpEvently: from n/a through 4.1.2.
AnalizadaCrítica (9.8)9.4%⚠ Explotación activa💥 ExploitOracle Peoplesoft Enterprise Peopletools11/6/202623/7/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise…
AplazadaMedia (6.3)0.26%—Magepeople WptravellyAI26/5/202624/7/2026
Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through 2.1.5.
AplazadaMedia (4.3)0.25%—Magepeople INC WpbookinglyAI26/5/202624/7/2026
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.
AplazadaMedia (5.3)0.19%—Magepeople Taxi Booking Manager FOR WoocommerceAI26/5/202624/7/2026
Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.1.
AplazadaMedia (6.5)0.42%—Magepeople WpbookinglyAI20/5/202624/7/2026
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.
AplazadaMedia (5.5)0.47%—Lasuite PeopleAI8/5/202617/6/2026
People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0, a user holding the Administrator role on a mail domain could send a crafted invitation request to promote any existing user (including users with no current domain access) to the Owner role. The…
AplazadaMedia (5.3)0.17%—Mage-people BUS Ticket Booking With Seat ReservationAI7/5/20267/10/2026
Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bus Ticket Booking with Seat Reservation: from n/a before 5.6.8.
AplazadaMedia (5.3)0.43%—Codepeople Booking Calendar Contact FormAI24/4/202617/6/2026
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.5)0.22%—Magepeople Taxi Booking Manager FOR WoocommerceAI23/4/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.0.
AnalizadaMedia (5.7)0.32%—Oracle Peoplesoft Enterprise CS Student Records21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records.…
AnalizadaAlta (8.1)0.36%—Oracle Peoplesoft Enterprise Peopletools21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks…
AnalizadaMedia (5.4)0.21%—Oracle Peoplesoft Enterprise Peopletools21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks…
AnalizadaMedia (6.5)0.35%—Oracle Peoplesoft Enterprise FIN Project Costing21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Project Costing.…
AnalizadaMedia (6.5)0.35%—Oracle Peoplesoft Enterprise FIN Maintenance Management21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN…
AnalizadaMedia (6.5)0.39%—Oracle Peoplesoft Enterprise FIN Contracts21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Contracts. Successful attacks…
Orbitaley — Vulnerabilidades