Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.5) | 0.29% | — | Oracle E-business SuiteAIOracle HrmsAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (India). While the vulnerability… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Oracle E-business SuiteAIOracle HrmsAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle HRMS (India). Successful attacks of… | |
| Pendiente de análisis | Alta (8.1) | 0.35% | — | Oracle E-business SuiteAIOracle HrmsAI | 15/9/2026 | 20/9/2026 | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (India). Successful attacks of… | |
| Aplazada | Baja (2) | 0.23% | — | Peoplesoft HrmsAI | 19/1/2026 | 17/6/2026 | A vulnerability was detected in pbrong hrms 1.0.1. The affected element is the function UpdateRecruitmentById of the file /handler/recruitment.go. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Media (6.1) | 0.31% | — | 104 Corporation EhrmsAI | 28/4/2025 | 17/6/2026 | The eHRMS from 104 Corporation has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Aplazada | Media (6.9) | 0.53% | — | Peoplesoft HrmsAI | 2/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resource.go. The manipulation of the argument user_cookie leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (4.3) | 1.9% | — | Unit4 Prosoft Hrms | 25/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4 Prosoft HRMS before 8.14.330.43 allows remote attackers to inject arbitrary web script or HTML via the txtUserID parameter. | |
| Modificada | Media (5.5) | 1.5% | — | Oracle Peoplesoft Enterprise HrmsOracle Peoplesoft Products | 18/10/2011 | 16/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 8.9 allows remote authenticated users to affect confidentiality and integrity, related to Job Profile Manager (JPM). | |
| Modificada | Media (4) | 1.6% | — | Oracle Peoplesoft Enterprise HrmsOracle Peoplesoft Products | 18/10/2011 | 16/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.0 and 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Talent Acquisition Manager. | |
| Modificada | Media (5.5) | 1.5% | — | Oracle Peoplesoft Enterprise HrmsOracle Peoplesoft Products | 18/10/2011 | 16/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Candidate Gateway. | |
| Modificada | Media (4) | 1.00% | — | Oracle Peoplesoft Enterprise HrmsOracle Peoplesoft Products | 21/7/2011 | 16/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.0 Bundle #17 allows remote authenticated users to affect confidentiality via unknown vectors related to ePerformance. | |
| Modificada | Media (5.5) | 1.1% | — | Oracle Peoplesoft Enterprise HrmsOracle Peoplesoft Products | 21/7/2011 | 16/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 8.9 Update 2011-D allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Global Payroll Core. | |
| Modificada | Media (5.5) | 0.99% | — | Oracle Peoplesoft Enterprise HrmsOracle Peoplesoft Products | 21/7/2011 | 16/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1, Bundle, and #6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Manager. | |
| Modificada | Media (4) | 0.96% | — | Oracle Peoplesoft Enterprise HrmsOracle Peoplesoft Products | 21/7/2011 | 16/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 8.9, Bundle, #24, 9.0, Bundle, #17, 9.1, Bundle, and #6 allows remote authenticated users to affect confidentiality via unknown vectors related to Talent Acquisition Manager. | |
| Modificada | Media (5.5) | 1.3% | — | Oracle Peoplesoft Enterprise Hrms | 20/4/2011 | 16/6/2026 | Unspecified vulnerability in Oracle PeopleSoft Enterprise HRMS 9.0 Update 2011-B and 9.1 Update 2011-B allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Global Payroll Core. | |
| Modificada | Media (5.5) | 1.3% | — | Oracle Peoplesoft Enterprise Hrms | 20/4/2011 | 16/6/2026 | Unspecified vulnerability in Oracle PeopleSoft Enterprise HRMS 9.0 Update 2011-B and 9.1 Update 2011-B allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Global Payroll - Spain. | |
| Modificada | Media (5.5) | 1.3% | — | Oracle Peoplesoft Enterprise Hrms | 20/4/2011 | 16/6/2026 | Unspecified vulnerability in Oracle PeopleSoft Enterprise HRMS 9.0 Tax Update 11-B and 9.1 Tax Update 11-B allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Global Payroll - North America. | |
| Modificada | Media (5.5) | 0.87% | — | Oracle Peoplesoft Enterprise Hrms | 20/4/2011 | 16/6/2026 | Unspecified vulnerability in Oracle PeopleSoft Enterprise HRMS 9.0 Bundle #15 and 9.1 Bundle #5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Manager. | |
| Modificada | Media (5.5) | 0.87% | — | Oracle Peoplesoft Enterprise Hrms | 20/4/2011 | 16/6/2026 | Unspecified vulnerability in Oracle PeopleSoft Enterprise HRMS 9.0 Bundle #15 and 9.1 Bundle #5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Pension Administration. | |
| Modificada | Media (5.5) | 0.91% | — | Oracle Peoplesoft Enterprise Hrms | 20/4/2011 | 16/6/2026 | Unspecified vulnerability in Oracle PeopleSoft Enterprise HRMS 9.1 Bundle #5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to ePerformance. | |
| Modificada | Media (5.5) | 0.91% | — | Oracle Peoplesoft Enterprise Hrms | 20/4/2011 | 16/6/2026 | Unspecified vulnerability in Oracle PeopleSoft Enterprise HRMS 9.0 Bundle #15 and 9.1 Bundle #5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to ePerformance. | |
| Modificada | Media (4.3) | 1.2% | — | Peoplesoft Hrms | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts. |