Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
312 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.40% | — | Oracle Trading Community | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks… | |
| Modificada | Crítica (9.8) | 8.7% | 💥 Exploit | Invisioncommunity | 7/6/2024 | 17/6/2026 | Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be… | |
| Aplazada | Alta (7.2) | 0.70% | — | Invision CommunityAI | 7/6/2024 | 17/6/2026 | Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugins/ directory… | |
| Aplazada | Media (6.3) | 0.78% | — | OtrsAIOtrs Community EditionAI | 6/6/2024 | 17/6/2026 | The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits authenticated agents or customer users to upload potentially harmful files to directories accessible by the web server, potentially leading to the execution of local code like Perl scripts. This issue… | |
| Aplazada | Media (5.4) | 0.48% | — | ANT Media Server Community EditionAI | 14/5/2024 | 17/6/2026 | Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users. All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor… | |
| Aplazada | Crítica (10) | 1.00% | — | Uvdesk CommunityAI | 25/4/2024 | 17/6/2026 | Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3. | |
| Aplazada | Media (4.3) | 0.18% | — | Peepso CommunityAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.3.1.1. | |
| Aplazada | Alta (7.5) | 0.84% | 💥 PoC | Sheetjs Community EditionAI | 5/4/2024 | 17/6/2026 | SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS). | |
| Aplazada | Alta (7.1) | 0.36% | — | Uvdesk Community SkeletonAI | 2/4/2024 | 17/6/2026 | Improper Privilege Management in uvdesk/community-skeleton | |
| Aplazada | Media (5.3) | 0.44% | — | Peepso CommunityAI | 28/3/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.2.7.0. | |
| Aplazada | Media (5.3) | 0.51% | — | Peepso CommunityAI | 26/3/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.0.9.0. | |
| Modificada | Alta (7.5) | 0.56% | — | Steve-community Steve | 13/2/2024 | 17/6/2026 | SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions. | |
| Modificada | Alta (7.5) | 0.62% | — | Steve-community Ocpp-jaxb | 26/12/2023 | 17/6/2026 | SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL exception in applications, and may undermine… | |
| Modificada | Media (6.1) | 0.49% | — | Communitydeveloper Amazzing Filter | 28/11/2023 | 17/6/2026 | Cross Site Scripting (XSS) in Search filters in Prestashop Amazzing filter version up to version 3.2.5, allows remote attackers to inject arbitrary JavaScript code. | |
| Modificada | Crítica (9.8) | 1.2% | 💥 PoC | Uvdesk Community-skeleton | 23/10/2023 | 17/6/2026 | UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application. | |
| Modificada | Media (5.3) | 1.2% | 💥 PoC | Koha-community Koha Library Software | 11/10/2023 | 17/6/2026 | File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl component. | |
| Modificada | Alta (7.5) | 1.4% | — | Koha-community Koha Library Software | 11/10/2023 | 17/6/2026 | SQL Injection vulnerability in Koha Library Software 23.0.5.04 and before allows a remote attacker to obtain sensitive information via the intranet/cgi bin/cataloging/ysearch.pl. component. | |
| Modificada | Media (6.1) | 0.69% | — | Uvdesk Community-skeleton | 4/4/2023 | 17/6/2026 | Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the application does not correctly validate the message sent by the clients in the ticket. | |
| Modificada | Alta (8.8) | 1.6% | — | Uvdesk Community-skeleton | 4/4/2023 | 17/6/2026 | Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers. | |
| Modificada | Media (4.8) | 0.39% | — | Community Events Project Community Events | 23/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions. | |
| Modificada | Media (4.8) | 0.40% | — | Uvdesk Community-skeleton | 6/3/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0. | |
| Modificada | Media (6.1) | 0.59% | — | Hitachi Community Plugin Framework | 21/12/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in Webdetails cpf up to 9.5.0.0-80. Affected is an unknown function of the file core/src/main/java/pt/webdetails/cpf/packager/DependenciesPackage.java. The manipulation of the argument baseUrl leads to cross site scripting. It is possible to launch the attack… | |
| Modificada | Crítica (9.1) | 1.2% | — | Invisioncommunity IPS Community Suite | 13/6/2022 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by an unauthenticated user. | |
| Modificada | Alta (8.8) | 0.43% | — | Tibco Businessconnect Trading Community Management | 18/5/2022 | 17/6/2026 | The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cross-Site Request Forgery (CSRF) on the affected system. A successful attack using this vulnerability… | |
| Modificada | Media (6.1) | 0.62% | — | Tibco Businessconnect Trading Community Management | 18/5/2022 | 17/6/2026 | The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow an unauthenticated attacker with network access to execute scripts targeting the affected system or the victim's local system.… |