Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.31% | — | Rusalex Wordpress-to-candidate FOR Salesforce CRMAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RusAlex WordPress-to-candidate for Salesforce CRM salesforce-wordpress-to-candidate allows Reflected XSS.This issue affects WordPress-to-candidate for Salesforce CRM: from n/a through <= 1.0.1. | |
| Modificada | Alta (7.5) | 1.2% | — | Dfinity Candid | 8/12/2023 | 17/6/2026 | The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For example, if the payload is `record { * ; empty }` and the canister interface expects `record { * }` then the Rust candid decoder treats empty as an extra field required by the type. The problem with the… | |
| Modificada | Media (6.1) | 1.1% | — | Auieo Candidats | 3/11/2022 | 17/6/2026 | CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks. | |
| Modificada | Media (6.1) | 1.1% | — | Auieo Candidats | 3/11/2022 | 17/6/2026 | CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks. | |
| Modificada | Media (6.1) | 1.1% | — | Auieo Candidats | 3/11/2022 | 17/6/2026 | CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks. | |
| Modificada | Media (6.1) | 1.2% | — | Auieo Candidats | 3/11/2022 | 17/6/2026 | CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks. | |
| Modificada | Alta (7.5) | 0.86% | — | Auieosoftware Candidats | 3/11/2022 | 17/6/2026 | CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable to XXE. | |
| Modificada | Crítica (9.8) | 1.3% | — | Auieo Candidats | 3/11/2022 | 17/6/2026 | CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks. | |
| Modificada | Alta (8.8) | 0.45% | — | Auieo Candidats | 3/11/2022 | 17/6/2026 | CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions. | |
| Modificada | Alta (8.8) | 1.0% | — | Auieo Candidats | 3/11/2022 | 17/6/2026 | CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the files uploaded by the user. | |
| Modificada | Media (6.5) | 0.99% | — | Auieo Candidats | 18/8/2022 | 17/6/2026 | CandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via the 'userID' parameter, in '/index.php?m=candidates&a=show' via the 'candidateID', in '/index.php?m=joborders&a=show' via the 'jobOrderID' and '/index.php?m=companies&a=show' via the 'companyID'… | |
| Modificada | Media (6.5) | 0.92% | — | Oracle Peoplesoft Enterprise HCM Candidate Gateway | 21/7/2021 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Candidate Gateway product of Oracle PeopleSoft (component: e-mail notification). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Candidate… | |
| Modificada | Media (5.4) | 0.77% | — | Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway | 15/7/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HRMS product of Oracle PeopleSoft (component: Time and Labor). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HRMS. Successful attacks of this… | |
| Modificada | Media (6.1) | 1.0% | — | Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway | 15/4/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HRMS product of Oracle PeopleSoft (component: Candidate Gateway). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HRMS. Successful attacks require… | |
| Modificada | Alta (8.8) | 0.60% | — | Auieo Candidats | 22/2/2020 | 17/6/2026 | CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI. | |
| Modificada | Media (6.1) | 0.98% | — | Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway | 23/4/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: Candidate Gateway). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HRMS. Successful… | |
| Modificada | Media (4.8) | 1.00% | — | Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote administrators to affect confidentiality and integrity via vectors related to Candidate Gateway. | |
| Modificada | Alta (7.5) | 8.6% | — | Candidate-application-form Project Candidate-application-form | 6/10/2016 | 17/6/2026 | Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin | |
| Modificada | Alta (7.5) | 0.99% | — | Nicholas Berry Candid | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in image/view.php in CANDID allows remote attackers to execute arbitrary SQL commands via the image_id parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Nicholas Berry Candid | 1/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id parameter. |