Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

312 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.40%—Oracle Trading Community16/7/202417/6/2026
Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks…
ModificadaCrítica (9.8)8.7%💥 ExploitInvisioncommunity7/6/202417/6/2026
Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be…
AplazadaAlta (7.2)0.70%—Invision CommunityAI7/6/202417/6/2026
Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugins/ directory…
AplazadaMedia (6.3)0.78%—OtrsAIOtrs Community EditionAI6/6/202417/6/2026
The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits authenticated agents or customer users to upload potentially harmful files to directories accessible by the web server, potentially leading to the execution of local code like Perl scripts. This issue…
AplazadaMedia (5.4)0.48%—ANT Media Server Community EditionAI14/5/202417/6/2026
Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users. All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor…
AplazadaCrítica (10)1.00%—Uvdesk CommunityAI25/4/202417/6/2026
Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.
AplazadaMedia (4.3)0.18%—Peepso CommunityAI12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.3.1.1.
AplazadaAlta (7.5)0.84%💥 PoCSheetjs Community EditionAI5/4/202417/6/2026
SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).
AplazadaAlta (7.1)0.36%—Uvdesk Community SkeletonAI2/4/202417/6/2026
Improper Privilege Management in uvdesk/community-skeleton
AplazadaMedia (5.3)0.44%—Peepso CommunityAI28/3/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.2.7.0.
AplazadaMedia (5.3)0.51%—Peepso CommunityAI26/3/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.0.9.0.
ModificadaAlta (7.5)0.56%—Steve-community Steve13/2/202417/6/2026
SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions.
ModificadaAlta (7.5)0.62%—Steve-community Ocpp-jaxb26/12/202317/6/2026
SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL exception in applications, and may undermine…
ModificadaMedia (6.1)0.49%—Communitydeveloper Amazzing Filter28/11/202317/6/2026
Cross Site Scripting (XSS) in Search filters in Prestashop Amazzing filter version up to version 3.2.5, allows remote attackers to inject arbitrary JavaScript code.
ModificadaCrítica (9.8)1.2%💥 PoCUvdesk Community-skeleton23/10/202317/6/2026
UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.
ModificadaMedia (5.3)1.2%💥 PoCKoha-community Koha Library Software11/10/202317/6/2026
File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl component.
ModificadaAlta (7.5)1.4%—Koha-community Koha Library Software11/10/202317/6/2026
SQL Injection vulnerability in Koha Library Software 23.0.5.04 and before allows a remote attacker to obtain sensitive information via the intranet/cgi bin/cataloging/ysearch.pl. component.
ModificadaMedia (6.1)0.69%—Uvdesk Community-skeleton4/4/202317/6/2026
Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the application does not correctly validate the message sent by the clients in the ticket.
ModificadaAlta (8.8)1.6%—Uvdesk Community-skeleton4/4/202317/6/2026
Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.
ModificadaMedia (4.8)0.39%—Community Events Project Community Events23/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions.
ModificadaMedia (4.8)0.40%—Uvdesk Community-skeleton6/3/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0.
ModificadaMedia (6.1)0.59%—Hitachi Community Plugin Framework21/12/202217/6/2026
A vulnerability classified as problematic has been found in Webdetails cpf up to 9.5.0.0-80. Affected is an unknown function of the file core/src/main/java/pt/webdetails/cpf/packager/DependenciesPackage.java. The manipulation of the argument baseUrl leads to cross site scripting. It is possible to launch the attack…
ModificadaCrítica (9.1)1.2%—Invisioncommunity IPS Community Suite13/6/202217/6/2026
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by an unauthenticated user.
ModificadaAlta (8.8)0.43%—Tibco Businessconnect Trading Community Management18/5/202217/6/2026
The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cross-Site Request Forgery (CSRF) on the affected system. A successful attack using this vulnerability…
ModificadaMedia (6.1)0.62%—Tibco Businessconnect Trading Community Management18/5/202217/6/2026
The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow an unauthenticated attacker with network access to execute scripts targeting the affected system or the victim's local system.…