Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
312 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.58% | — | Tibco Businessconnect Trading Community Management | 18/5/2022 | 17/6/2026 | The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using these vulnerabilities… | |
| Modificada | Crítica (9.8) | 1.6% | — | Oretnom23 Simple Music Cloud Community System | 21/1/2022 | 17/6/2026 | An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php. | |
| Modificada | Media (5.4) | 0.55% | — | Alfresco Community ShareAlfresco Share | 21/10/2021 | 17/6/2026 | An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An evasion of the XSS filter for HTML input validation in the Alfresco Share User Interface leads to stored XSS that could be exploited by an attacker (given that he has privileges on the content… | |
| Modificada | Media (5.7) | 0.52% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 20/10/2021 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Notification Framework). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the… | |
| Modificada | Alta (7.5) | 53% | 💥 Exploit | Payara Micro Community | 23/9/2021 | 17/6/2026 | Payara Micro Community 5.2021.6 and below allows Directory Traversal. | |
| Modificada | Media (5.4) | 0.81% | — | Invisioncommunity Invision Power Board | 17/8/2021 | 17/6/2026 | Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an admin to install widgets, disclosure of the… | |
| Modificada | Media (6.1) | 0.77% | — | Invisioncommunity Invision Power Board | 17/8/2021 | 17/6/2026 | Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function. | |
| Modificada | Media (6.1) | 0.83% | — | Community Events Project Community Events | 2/8/2021 | 17/6/2026 | The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator | |
| Modificada | Media (6.5) | 1.5% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2021 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS… | |
| Modificada | Alta (8.8) | 20% | — | Invisioncommunity IPS Community Suite | 1/6/2021 | 17/6/2026 | Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction method. | |
| Modificada | Media (5.5) | 0.35% | — | Oracle VirtualizationRedhat AnsibleRedhat Ansible TowerRedhat Cisco Nx-os Collection+4 | 26/5/2021 | 17/6/2026 | A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality.… | |
| Modificada | Baja (3.5) | 0.72% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 22/4/2021 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Frameworks). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.… | |
| Modificada | Alta (8.8) | 2.6% | — | Endian Firewall Community | 15/2/2021 | 17/6/2026 | Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup comment. | |
| Modificada | Alta (8.8) | 1.4% | — | Invisioncommunity IPS Community Suite | 8/1/2021 | 17/6/2026 | Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in applications/downloads/api/files.php). | |
| Modificada | Media (6.1) | 0.64% | — | Invisioncommunity IPS Community Suite | 5/1/2021 | 17/6/2026 | Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment. | |
| Modificada | Media (4.8) | 1.1% | 💥 Exploit | Invisioncommunity Community | 30/12/2020 | 9/7/2026 | Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attacker to inject the XSS payload in Field Name and each time any user will open that, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload. | |
| Modificada | Alta (7.5) | 1.4% | — | Ansible Collections Project Community.crypto | 29/10/2020 | 17/6/2026 | A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality | |
| Modificada | Media (5) | 0.95% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 15/4/2020 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Self-Service). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.… | |
| Modificada | Media (6.1) | 3.5% | — | Invisioncommunity Invision Power BoardMicrosoft Internet Explorer | 13/3/2020 | 16/6/2026 | Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment. | |
| Modificada | Media (5.4) | 0.55% | — | Telligent Community | 13/2/2020 | 16/6/2026 | XSS in Telligent Community 5.6.583.20496 via a flash file and related to the allowScriptAccess parameter. | |
| Modificada | Crítica (9.8) | 1.8% | — | Invisioncommunity Invision Power Board | 12/2/2020 | 16/6/2026 | Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution. | |
| Modificada | Crítica (9.8) | 7.4% | 💥 Exploit | Invisioncommunity Invision Power Board | 9/1/2020 | 16/6/2026 | Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file. | |
| Modificada | Baja (3.3) | 0.32% | — | Redhat Jboss Community Application ServerRedhat Jboss Enterprise WEB Server | 6/12/2019 | 16/6/2026 | An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies | |
| Modificada | Media (6.1) | 1.9% | — | Invisioncommunity Invision Power Board | 2/3/2019 | 17/6/2026 | Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution. | |
| Modificada | Baja (3.1) | 1.1% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 16/1/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community component of Oracle PeopleSoft Products (subcomponent: Frameworks). Supported versions that are affected are 9.0 and 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS… |