Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.6)0.73%—Adobe Experience Manager Forms JEEAI22/9/202623/9/2026
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope…
Pendiente de análisisAlta (8.7)0.81%—Adobe Experience Manager Forms JEEAI22/9/202623/9/2026
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction.…
Pendiente de análisisCrítica (9.1)1.2%—Adobe Experience Manager Forms JEEAI22/9/202623/9/2026
Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user…
Pendiente de análisisCrítica (10)1.2%—Adobe Experience Manager Forms JEEAI22/9/202625/9/2026
Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is…
Pendiente de análisisAlta (8.1)1.2%—Adobe Experience Manager Forms JEEAI22/9/202622/9/2026
Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the…
Pendiente de análisisAlta (7.1)1.5%—Adobe Experience Manager Forms JEEAI22/9/202624/9/2026
Adobe Experience Manager Forms JEE is affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of…
AnalizadaAlta (8.6)77%—Adobe Experience Manager Forms5/8/202517/6/2026
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed.…
AnalizadaCrítica (10)88%⚠ Explotación activaAdobe Experience Manager Forms5/8/202517/6/2026
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is…
ModificadaMedia (5.8)2.1%—Adobe Experience Manager Forms Add-on10/12/202017/6/2026
AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2) have a blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability could be exploited by an unauthenticated attacker to gather information about internal systems that reside on the…
ModificadaAlta (7.5)3.8%—Adobe Experience ManagerAdobe Experience Manager Forms10/9/202017/6/2026
An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.
ModificadaCrítica (9)2.8%—Adobe Experience ManagerAdobe Experience Manager Forms10/9/202017/6/2026
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page…
ModificadaMedia (6.1)1.5%—Adobe Experience Manager Forms22/10/201917/6/2026
Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
ModificadaMedia (6.1)1.6%—Adobe Experience Manager Forms29/5/201917/6/2026
Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
ModificadaAlta (7.5)4.8%—Adobe Experience Manager Forms9/5/201717/6/2026
Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service in AEM Forms.
ModificadaMedia (6.1)2.6%—Adobe Experience Manager FormsAdobe Livecycle15/12/201617/6/2026
Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that could be used in cross-site scripting attacks.