Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.2)0.13%—Oracle Planning AND Budgeting Cloud ServiceAIOracle HyperionAIOracle EPM AgentAI20/1/202617/6/2026
Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Planning and Budgeting Cloud Service…
AnalizadaMedia (4.2)0.15%—Oracle Planning AND Budgeting Cloud Service20/1/202617/6/2026
Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Planning and Budgeting Cloud Service…
AplazadaAlta (8.5)0.31%—Lexmark Cloud ServicesAI19/8/202517/6/2026
A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization
AplazadaCrítica (9.4)0.40%—Growatt Cloud ServiceAI19/7/202517/6/2026
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.
AnalizadaAlta (7.8)0.33%—Ivanti Cloud Services Appliance13/5/202517/6/2026
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.
AplazadaBaja (3.5)0.26%—Whatsapp Cloud ServiceAI20/3/202517/6/2026
The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with BIGPRETZEL.
AnalizadaAlta (7.2)22%—Ivanti Cloud Services Appliance11/2/202517/6/2026
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaMedia (5.3)1.2%—Ivanti Cloud Services Appliance11/2/202517/6/2026
Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.
AnalizadaAlta (7.2)23%—Ivanti Cloud Services Appliance10/12/202417/6/2026
SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
AnalizadaAlta (7.2)7.7%—Ivanti Cloud Services Appliance10/12/202417/6/2026
Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaCrítica (9.8)4.9%—Ivanti Cloud Services Appliance10/12/202417/6/2026
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
AnalizadaAlta (7.2)16%—Ivanti Endpoint Manager Cloud Services Appliance8/10/202417/6/2026
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
AnalizadaAlta (7.2)60%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance8/10/202417/6/2026
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
AnalizadaAlta (7.2)44%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance8/10/20241/10/2026
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
AnalizadaCrítica (9.1)99%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance19/9/202417/6/2026
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
AnalizadaAlta (7.2)89%⚠ Explotación activaIvanti Cloud Services Appliance10/9/202417/6/2026
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
AplazadaCrítica (9.4)0.50%—Ewelink Cloud ServiceAI31/7/202417/6/2026
When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.
ModificadaMedia (5.4)0.60%—Adobe Experience ManagerAdobe Experience Manager Cloud Service15/12/202317/6/2026
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
ModificadaMedia (5.4)0.60%—Adobe Experience ManagerAdobe Experience Manager Cloud Service15/12/202317/6/2026
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…
ModificadaMedia (5.4)0.60%—Adobe Experience ManagerAdobe Experience Manager Cloud Service15/12/202317/6/2026
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…
ModificadaMedia (5.4)0.60%—Adobe Experience ManagerAdobe Experience Manager Cloud Service15/12/202317/6/2026
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…
ModificadaMedia (5.4)0.60%—Adobe Experience ManagerAdobe Experience Manager Cloud Service15/12/202317/6/2026
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…
ModificadaMedia (5.4)0.60%—Adobe Experience ManagerAdobe Experience Manager Cloud Service15/12/202317/6/2026
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…
ModificadaMedia (5.4)0.60%—Adobe Experience ManagerAdobe Experience Manager Cloud Service15/12/202317/6/2026
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…
ModificadaMedia (5.4)0.60%—Adobe Experience ManagerAdobe Experience Manager Cloud Service15/12/202317/6/2026
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…