Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.28% | — | IBM Tivoli Workload Scheduler | 14/3/2018 | 17/6/2026 | IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with improper permissions that could allow a local user to with special access to gain root privileges. IBM X-Force ID: 138208. | |
| Modificada | Media (6.1) | 30% | 💥 PoC | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Baja (3.3) | 0.27% | — | IBM Tivoli Workload Scheduler | 13/12/2017 | 17/6/2026 | IBM Tivoli Workload Scheduler 8.6.0, 9.1.0, and 9.2.0 could disclose sensitive information to a local attacker due to improper permission settings. IBM X-Force ID: 134638. | |
| Modificada | Media (6.1) | 1.0% | — | Oracle Real-time Scheduler | 24/4/2017 | 17/6/2026 | Vulnerability in the Oracle Real-Time Scheduler component of Oracle Utilities Applications (subcomponent: Mobile Communications Platform). Supported versions that are affected are 2.2.0.3.13, 2.3.0.0 and 2.3.0.1. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Alta (8.6) | 2.0% | — | Cisco Tidal Enterprise Scheduler | 15/3/2017 | 17/6/2026 | A vulnerability in the Client Manager Server of Cisco Workload Automation and Cisco Tidal Enterprise Scheduler could allow an unauthenticated, remote attacker to retrieve any file from the Client Manager Server. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by… | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Phpjabbers Appointment Scheduler | 13/1/2015 | 17/6/2026 | Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Phpjabbers Appointment Scheduler | 13/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices… | |
| Modificada | Media (5.8) | 2.5% | — | SOS Jobscheduler | 23/9/2014 | 17/6/2026 | XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference. | |
| Modificada | Media (4) | 2.6% | — | SOS Jobscheduler | 11/9/2014 | 17/6/2026 | Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with the info permission to read arbitrary files in the webroot via unspecified vectors. | |
| Modificada | Media (4.3) | 2.2% | — | SOS Jobscheduler | 11/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote attackers to inject arbitrary web script or HTML via the hash property (location.hash). | |
| Modificada | Media (5) | 1.4% | — | SAP OIL Industry Solution Traders AND Schedulers Workbench | 9/6/2014 | 17/6/2026 | The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |
| Modificada | Media (6) | 0.31% | — | Cisco Tidal Enterprise Scheduler | 26/5/2014 | 17/6/2026 | The Agent in Cisco Tidal Enterprise Scheduler (TES) 6.1 and earlier allows local users to gain privileges via crafted Tidal Job Buffers (TJB) parameters, aka Bug ID CSCuo33074. | |
| Modificada | Media (6.4) | 1.4% | — | Sebastien Corbin Make Meeting Scheduler Module | 9/10/2013 | 16/6/2026 | The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to bypass intended access restrictions for a poll via a direct request to the node's URL instead of the hashed URL. | |
| Modificada | Media (6) | 1.1% | — | Simplenews Scheduler Project Simplenews Scheduler | 3/12/2012 | 16/6/2026 | The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by cron. | |
| Modificada | Alta (7.5) | 1.4% | — | Hitachi Groupmax Groupware ServerHitachi Groupmax Scheduler Server SETHitachi Groupmax Server SET | 11/9/2009 | 16/6/2026 | Unspecified vulnerability in Hitachi Groupmax Groupware Server 07-00 through 07-50-/A, Groupmax Server Set 03-00 through 06-52, Groupware Server Set 03-00 through 06-52, and Scheduler Server Set 03-00 through 06-52 has unknown impact and attack vectors related to invalid access rights. | |
| Modificada | Media (6.5) | 1.3% | — | Oracle Database SchedulerOracle Database Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the Database Scheduler component in Oracle Database 10.2.0.4 and 11.1.0.6 has unknown impact and local attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is an untrusted search path… | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Phpjobscheduler | 16/11/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter to (1) add-modify.php, (2) delete.php, (3) modify.php, and (4) phpjobscheduler.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpjobscheduler | 16/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in firepjs.php in Phpjobscheduler 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter. NOTE: the provenance of this information is unknown; details are obtained from third party sources. | |
| Modificada | Media (5.8) | 1.3% | — | Hitachi Groupmax World Wide WEBHitachi Groupmax World Wide WEB DesktopHitachi Groupmax World Wide WEB Desktop SchedulerHitachi Groupmax World Wide WEB Scheduler | 1/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web, World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for Scheduler, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | |
| Modificada | Alta (10) | 6.7% | 💥 Exploit | Crosswind Cyberscheduler | 2/7/2001 | 16/6/2026 | Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter. |