Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

176 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.9)0.23%—Fivestarplugins Five Star Business Profile AND SchemaAI4/10/20266/10/2026
The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and…
AnalizadaCrítica (9.9)0.43%—Oracle Business Process Management Suite21/7/20267/8/2026
Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle…
AplazadaCrítica (9.1)0.66%—Five Star Business ProfileAISchemaAI2/7/20262/7/2026
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
AnalizadaMedia (6.1)0.24%—Oracle Business Process Management Suite21/4/202617/6/2026
Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
AplazadaMedia (5.3)0.24%—Appian Enterprise Business Process ManagementAI19/8/202517/6/2026
A security issue has been identified in Appian Enterprise Business Process Management version 25.3. The vulnerability is related to incorrect access control, which under certain conditions could allow unauthorized access to information. NOTE: this has been disputed because the CVE Record information does not originate…
AplazadaAlta (8.5)0.37%💥 ExploitPandasecurity Global ProtectionAIPandasecurity Antivirus PROAIPandasecurity Small Business ProtectionAIPandasecurity Internet SecurityAI15/7/202517/6/2026
PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges.…
ModificadaAlta (8.8)0.27%—Auto Publish FOR Google MY Business Project Auto Publish FOR Google MY Business9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson Auto Publish for Google My Business plugin <= 3.7 versions.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (6.1)0.38%—Bestdivichild Business PRO4/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vathemes Business Pro theme <= 1.10.4 versions.
ModificadaMedia (5.4)0.47%—Auto Publish FOR Google MY Business Project Auto Publish FOR Google MY Business23/1/202317/6/2026
The WP Google My Business Auto Publish WordPress plugin before 3.4 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModificadaAlta (7.5)1.1%—Digiwin Business Process Management20/7/202217/6/2026
Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.
ModificadaMedia (5.3)0.84%—Digiwin Business Process Management20/7/202217/6/2026
Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
ModificadaCrítica (9.8)1.6%—Digiwin Business Process Management20/7/202217/6/2026
Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.
ModificadaMedia (6.5)0.36%—IBM Business Automation WorkflowIBM Business Process Manager31/5/202217/6/2026
IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, IBM Business Automation Workflow containers V21.0.1 - V21.0.3 20.0.0.1 through 20.0.0.2, IBM Business Process Manager 8.6.0.0 through 8.6.0.201803, and 8.5.0.0 through…
ModificadaMedia (4.9)0.93%—IBM Business Automation WorkflowIBM Business Process Manager18/3/202217/6/2026
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user credentials in plain clear text which can be read by a lprivileged user. IBM X-Force ID: 214346.
ModificadaMedia (5.4)0.60%—Fivestarplugins Five Star Business Profile AND Schema21/2/202217/6/2026
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of…
ModificadaAlta (8.8)54%—Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+2218/1/202217/6/2026
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
ModificadaCrítica (9.8)67%💥 PoCApache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+2418/1/202217/6/2026
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or…
ModificadaAlta (8.8)64%—Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+2218/1/202217/6/2026
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink…
ModificadaMedia (6.5)1.1%—IBM Business Automation WorkflowIBM Business Process ManagerIBM Workflow Process Service21/12/202117/6/2026
IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a privileged user to obtain highly sensitive information due to improper access controls. IBM X-Force ID: 209607.
ModificadaMedia (5.4)0.69%—IBM Business Automation WorkflowIBM Business Process ManagerIBM Workflow Process Service21/12/202117/6/2026
IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure…
ModificadaMedia (5.4)0.48%—IBM Business Automation WorkflowIBM Business Process Manager17/12/202117/6/2026
IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within…
ModificadaAlta (7.5)81%💥 PoCApache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+4214/12/202117/6/2026
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in…
AnalizadaCrítica (10)100%⚠ Explotación activa💥 ExploitSiemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+13910/12/202111/8/2026
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can…
ModificadaMedia (5.9)0.80%—IBM Business Automation WorkflowIBM Business Process Manager5/11/202117/6/2026
IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Orbitaley — Vulnerabilidades