Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.52% | — | Sos-berlin Jobscheduler | 5/2/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to inject arbitrary web script or HTML via JSON properties available from the REST API. | |
| Modificada | Alta (7.8) | 0.31% | — | IBM Tivoli Workload Scheduler | 16/10/2019 | 17/6/2026 | IBM Workload Scheduler Distributed 9.2, 9.3, 9.4, and 9.5 contains a vulnerability that could allow a local user to write files as root in the file system, which could allow the attacker to gain root privileges. IBM X-Force ID: 155997. | |
| Modificada | Alta (7.5) | 1.5% | — | Ttpsc THE Scheduler | 7/8/2019 | 17/6/2026 | The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the versions 5.2.1 and 3.3.7 | |
| Modificada | Crítica (9.8) | 16% | 💥 PoC | Softwareag QuartzOracle Apache Batik MapviewerOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+27 | 26/7/2019 | 17/6/2026 | initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Osthemeclub Timetable Schedule | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter. | |
| Modificada | Alta (7.8) | 2.5% | — | Pyconuk Conference-scheduler-cli | 28/8/2018 | 17/6/2026 | In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call. | |
| Modificada | Alta (7.8) | 0.28% | — | IBM Tivoli Workload Scheduler | 14/3/2018 | 17/6/2026 | IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with improper permissions that could allow a local user to with special access to gain root privileges. IBM X-Force ID: 138208. | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Quanticalabs Timetable Responsive Schedule | 17/2/2018 | 17/6/2026 | SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request. | |
| Modificada | Media (6.1) | 30% | 💥 PoC | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Baja (3.3) | 0.27% | — | IBM Tivoli Workload Scheduler | 13/12/2017 | 17/6/2026 | IBM Tivoli Workload Scheduler 8.6.0, 9.1.0, and 9.2.0 could disclose sensitive information to a local attacker due to improper permission settings. IBM X-Force ID: 134638. | |
| Modificada | Media (6.1) | 1.0% | — | Oracle Real-time Scheduler | 24/4/2017 | 17/6/2026 | Vulnerability in the Oracle Real-Time Scheduler component of Oracle Utilities Applications (subcomponent: Mobile Communications Platform). Supported versions that are affected are 2.2.0.3.13, 2.3.0.0 and 2.3.0.1. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Alta (8.8) | 0.55% | — | IBM Disposal AND Governance Management FOR ITIBM Global Retention Policy AND Schedule Management | 5/4/2017 | 17/6/2026 | IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM… | |
| Modificada | Alta (8.6) | 2.0% | — | Cisco Tidal Enterprise Scheduler | 15/3/2017 | 17/6/2026 | A vulnerability in the Client Manager Server of Cisco Workload Automation and Cisco Tidal Enterprise Scheduler could allow an unauthenticated, remote attacker to retrieve any file from the Client Manager Server. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by… | |
| Modificada | Media (4.3) | 1.2% | — | Nishishi Fumy Teachers Schedule Board | 31/3/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in schedule.cgi in Nishishi Factory Fumy Teacher's Schedule Board 1.10 through 2.21 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Phpjabbers Appointment Scheduler | 13/1/2015 | 17/6/2026 | Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Phpjabbers Appointment Scheduler | 13/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices… | |
| Modificada | Media (5.8) | 2.5% | — | SOS Jobscheduler | 23/9/2014 | 17/6/2026 | XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference. | |
| Modificada | Media (4) | 2.6% | — | SOS Jobscheduler | 11/9/2014 | 17/6/2026 | Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with the info permission to read arbitrary files in the webroot via unspecified vectors. | |
| Modificada | Media (4.3) | 2.2% | — | SOS Jobscheduler | 11/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote attackers to inject arbitrary web script or HTML via the hash property (location.hash). | |
| Modificada | Media (4.3) | 1.2% | — | IBM Atlas Ediscovery Process ManagementIBM Atlas SuiteIBM Disposal AND Governance Management FOR ITIBM Global Retention Policy AND Schedule Management | 29/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Atlas Suite (aka Atlas Policy Suite), as used in Atlas eDiscovery Process Management through 6.0.3, Disposal and Governance Management for IT through 6.0.3, and Global Retention Policy and Schedule Management through 6.0.3, allow remote attackers to inject… | |
| Modificada | Media (4.3) | 1.6% | — | WP Appointments Schedules Project WP Appointments Schedules | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in js/test.php in the Appointments Scheduler plugin 1.5 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | |
| Modificada | Media (5) | 1.4% | — | SAP OIL Industry Solution Traders AND Schedulers Workbench | 9/6/2014 | 17/6/2026 | The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |
| Modificada | Media (6) | 0.31% | — | Cisco Tidal Enterprise Scheduler | 26/5/2014 | 17/6/2026 | The Agent in Cisco Tidal Enterprise Scheduler (TES) 6.1 and earlier allows local users to gain privileges via crafted Tidal Job Buffers (TJB) parameters, aka Bug ID CSCuo33074. | |
| Modificada | Media (6.4) | 1.4% | — | IBM Atlas Ediscovery Process ManagementIBM Atlas SuiteIBM Disposal AND Governance Management FOR ITIBM Global Retention Policy AND Schedule Management | 10/1/2014 | 17/6/2026 | IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) do not properly validate sessions, which allows… |