Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

244 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.63%—Resque-scheduler Project Resque-scheduler13/12/20229/7/2026
Resque Scheduler version 1.27.4 is vulnerable to Cross-site scripting (XSS). A remote attacker could inject javascript code to the "{schedule_job}" or "args" parameter in /resque/delayed/jobs/{schedule_job}?args={args_id} to execute javascript at client side.
ModificadaAlta (7.5)1.3%—Apache Dolphinscheduler24/11/202217/6/2026
When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.
ModificadaCrítica (9.8)2.8%—Apache Dolphinscheduler23/11/202217/6/2026
Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher
ModificadaMedia (6.5)1.6%💥 PoCApache Dolphinscheduler1/11/202217/6/2026
When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher
ModificadaMedia (6.1)0.51%—Train Scheduler APP Project Train Scheduler APP1/11/202217/6/2026
A cross-site scripting (XSS) vulnerability in /admin/add-fee.php of Train Scheduler App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.
ModificadaCrítica (9.1)1.2%—Train Scheduler APP Project Train Scheduler APP31/10/202217/6/2026
A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /train_scheduler_app/?action=delete. The manipulation of the argument id leads to improper control of resource identifiers. The attack may be launched…
ModificadaMedia (6.5)1.6%💥 PoCApache Dolphinscheduler28/10/202217/6/2026
Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
ModificadaMedia (5.4)0.49%—Train Scheduler APP Project Train Scheduler APP27/10/20229/7/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Train Code, Train Name, and Destination text fields.
ModificadaAlta (8.8)0.43%—Backup Scheduler Project Backup Scheduler23/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability Backup Scheduler plugin <= 1.5.13 at WordPress.
ModificadaMedia (4.8)0.68%—Nsqua Simply Schedule Appointments29/8/202217/6/2026
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (5.3)1.9%💥 ExploitNsqua Simply Schedule Appointments29/8/202217/6/2026
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address
ModificadaMedia (6.1)0.50%—Motopress Timetable AND Event Schedule16/8/202217/6/2026
A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This affects an unknown part of the file /wp/?cpmvc_id=1&cpmvc_do_action=mvparse&f=datafeed&calid=1&month_index=1&method=adddetails&id=2 of the component Calendar Handler. The manipulation of the argument…
ModificadaMedia (6.1)0.58%—Motopress Timetable AND Event Schedule16/8/202217/6/2026
A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /wp-admin/admin-ajax.php of the component Quick Edit. The manipulation of the argument post_title with the input <img src=x onerror=alert`2`> leads to…
ModificadaAlta (7.1)0.19%—IBM Workload Scheduler10/8/202217/6/2026
IBM Workload Scheduler 9.4 and 9.5 could allow a local user to overwrite key system files which would cause the system to crash. IBM X-Force ID: 221187.
ModificadaMedia (5.4)0.69%—Ttpsc THE Scheduler13/7/202217/6/2026
The Transition Scheduler add-on 6.5.0 for Atlassian Jira is prone to stored XSS via the project name to the creation function.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+341/4/202217/6/2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to…
ModificadaAlta (7.5)2.0%—Apache Dolphinscheduler30/3/202217/6/2026
Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.
ModificadaMedia (6.1)0.80%—Myceliumdesign Conference Scheduler28/3/202217/6/2026
The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting.
ModificadaMedia (6.1)1.0%—Online Covid Vaccination Scheduler System Project Online Covid Vaccination Scheduler System24/1/202217/6/2026
Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid Vaccination Scheduler System v1 by oretnom23, allows attackers to execute arbitrary code via the lid parameter to /scheduler/addSchedule.php.
ModificadaCrítica (9.8)1.3%—Patient Appointment Scheduler System Project Patient Appointment Scheduler System24/1/202217/6/2026
SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitApache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+5114/12/202117/6/2026
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,…
AnalizadaCrítica (10)100%⚠ Explotación activa💥 ExploitSiemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+13910/12/202111/8/2026
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can…
ModificadaAlta (8.8)1.9%—Apache Dolphinscheduler1/11/202117/6/2026
In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
ModificadaAlta (8.1)1.6%—Online Covid Vaccination Scheduler System Project Online Covid Vaccination Scheduler System27/10/202117/6/2026
An SQL Injection vulnerability exists in Sourcecodester Online Covid Vaccination Scheduler System 1.0 via the username in lognin.php .
ModificadaMedia (6.5)1.2%—Motopress Timetable AND Event Schedule20/9/202117/6/2026
The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive data) of the user related to the Even Head of the Timeslot in the response when requesting the event Timeslot data with a user with the edit_posts capability. Combined with…
Orbitaley — Vulnerabilidades