Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.28% | — | MCP Content Manager LiteAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Content Manager | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager. Successful attacks… | |
| Analizada | Media (6.3) | 0.26% | — | Oracle Content Manager | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Cover Letter). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager. Successful attacks of… | |
| Aplazada | Alta (7.1) | 0.24% | — | Otwthemes Content Manager LightAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content Manager Light content-manager-light allows Reflected XSS.This issue affects Content Manager Light: from n/a through <= 3.2. | |
| Aplazada | Alta (7) | 0.19% | — | Opentext Secure Content ManagerAI | 17/4/2025 | 17/6/2026 | Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.This issue affects Secure Content Manager: 23.4. End-users can potentially exploit the vulnerability to execute malicious code in the trusted context of the thick-client application. | |
| Aplazada | Media (6.5) | 0.36% | — | Otwthemes Content Manager LightAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content Manager Light content-manager-light allows Stored XSS.This issue affects Content Manager Light: from n/a through <= 3.2. | |
| Aplazada | Media (5.1) | 0.46% | — | Opentext Secure Content ManagerAI | 22/11/2024 | 17/6/2026 | : Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This issue affects Secure Content Manager: from 10.1 before <24.4. End-users can potentially exploit the vulnerability to exclude audit trails from being recorded on the client side. | |
| Aplazada | Alta (8.5) | 0.38% | — | Content ManagerAI | 25/3/2024 | 17/6/2026 | By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform unauthorized operations. | |
| Analizada | Alta (8.8) | 0.40% | — | IBM Cp4ba - Filenet Content ManagerIBM Filenet Content Manager | 1/3/2024 | 17/6/2026 | IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual circumstances. IBM X-Force ID: 271656. | |
| Analizada | Media (5.3) | 0.75% | — | IBM Filenet Content Manager | 1/3/2024 | 17/6/2026 | IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 261115. | |
| Modificada | Media (5.4) | 0.37% | — | IBM Filenet Content Manager | 4/10/2023 | 17/6/2026 | IBM FileNet Content Manager 5.5.8, 5.5.10, and 5.5.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 259384. | |
| Modificada | Alta (8.8) | 1.8% | — | IBM Filenet Content Manager | 17/1/2022 | 17/6/2026 | IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346. | |
| Modificada | Alta (8.1) | 0.97% | — | Oracle Content Manager | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Content Item Manager). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager. Successful attacks… | |
| Modificada | Alta (7.8) | 2.0% | — | IBM Filenet Content Manager | 9/11/2020 | 17/6/2026 | IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 188736. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Filenet Content Manager | 23/7/2020 | 17/6/2026 | IBM FileNet Content Manager 5.5.3 and 5.5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181227. | |
| Modificada | Media (5.8) | 1.1% | — | Oracle Content Manager | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Content). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Content Manager. While the… | |
| Modificada | Media (4.4) | 0.30% | — | IBM Filenet Content Manager | 14/10/2019 | 17/6/2026 | IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into a log file that could be accessed by an administrator on the local machine. IBM X-Force ID: 166798. | |
| Modificada | Media (4.3) | 0.69% | — | Microfocus Content Manager | 30/8/2019 | 17/6/2026 | Information exposure in Micro Focus Content Manager, versions 9.1, 9.2 and 9.3. This vulnerability when configured to use an Oracle database, allows valid system users to gain access to a limited subset of records they would not normally be able to access when the system is in an undisclosed abnormal state. | |
| Modificada | Media (5.4) | 0.78% | — | Microfocus Content Manager | 7/8/2019 | 17/6/2026 | Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploited to manipulate data stored during another user’s CheckIn request. | |
| Modificada | Alta (7.5) | 1.7% | — | Microfocus Content Manager | 1/4/2019 | 17/6/2026 | An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to arbitrary locations on the… | |
| Modificada | Alta (8.2) | 1.5% | — | Oracle Content Manager | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Content Manager component of Oracle E-Business Suite (subcomponent: Cover Letter). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Media (6.5) | 6.0% | — | SDL WEB Content Manager | 2/1/2019 | 17/6/2026 | The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system. | |
| Modificada | Alta (7.1) | 1.9% | — | IBM Filenet Content Manager | 12/10/2018 | 17/6/2026 | IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150904. | |
| Modificada | Media (5.4) | 0.97% | — | IBM Filenet Content ManagerIBM Content Foundation | 6/7/2018 | 17/6/2026 | IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142893. | |
| Modificada | Media (5.4) | 0.97% | — | IBM Filenet Content ManagerIBM Content Foundation | 6/7/2018 | 17/6/2026 | IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142892. |