Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.2) | 0.12% | — | Crmeb Knowledge-paid SystemAI | 21/9/2026 | 1/10/2026 | CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information. | |
| Aplazada | Alta (7.1) | 0.25% | — | Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions. | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Knowledge Management | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful… | |
| Analizada | Media (6.1) | 0.13% | — | Oracle Knowledge Management | 21/7/2026 | 10/8/2026 | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks… | |
| Aplazada | Alta (8.5) | 0.19% | — | Ipknowledge Musetheque V4AIIpknowledge V4l1AI | 15/5/2026 | 17/6/2026 | Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected product, unexpected operations may be done. | |
| Aplazada | Media (4.8) | 0.13% | — | Ipknowledge Musetheque V4AI | 15/5/2026 | 17/6/2026 | Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script may be executed on a user's web browser when viewing the administration page showing the information of the file. | |
| Pendiente de análisis | Crítica (9.1) | 0.81% | — | Microsoft Asp.netAIMicrosoft IISAIDigital Knowledge KnowledgedeliverAI | 16/4/2026 | 17/6/2026 | Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks | |
| Analizada | Media (4.4) | 0.15% | — | IBM Knowledge Catalog | 25/3/2026 | 17/6/2026 | IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that could be read by a local privileged user. | |
| Aplazada | Media (4.3) | 0.14% | — | ADD Google Social Profiles TO Knowledge Graph BOXAI | 21/3/2026 | 17/6/2026 | The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's… | |
| Aplazada | Media (4.3) | 0.19% | — | Echoplugins Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in echoplugins Knowledge Base for Documentation, FAQs with AI Assistance echo-knowledge-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through <= 16.011.0. | |
| Aplazada | Media (6.5) | 0.17% | — | Basepress Knowledge Base Documentation & Wiki PluginAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BasePress Knowledge Base documentation & wiki plugin – BasePress basepress allows Stored XSS.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through <= 2.17.0.1. | |
| Aplazada | Media (6.5) | 0.19% | — | Xenioushk BWL Knowledge Base ManagerAI | 30/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Knowledge Base Manager bwl-kb-manager allows Stored XSS.This issue affects BWL Knowledge Base Manager: from n/a through <= 1.6.3. | |
| Aplazada | Media (4.8) | 0.26% | — | Public Knowledge Project OMPAIPublic Knowledge Project OJSAI | 20/11/2025 | 17/6/2026 | A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the argument manualInstructions leads to cross… | |
| Aplazada | Alta (8.8) | 0.53% | — | Designthemes Knowledge BaseAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9. | |
| Aplazada | Media (4.4) | 0.26% | — | Knowledge BaseAI | 18/7/2025 | 17/6/2026 | The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject… | |
| Analizada | Crítica (9.8) | 0.72% | — | Mmz-001 Knowledgegpt | 24/6/2025 | 17/6/2026 | An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component. | |
| Aplazada | Alta (7.1) | 0.13% | — | Devfelixmoira Knowledge Base MakerAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base – Knowledge Base Maker knowledge-base-maker allows Stored XSS.This issue affects Knowledge Base – Knowledge Base Maker: from n/a through <= 1.1.8. | |
| Aplazada | Media (6.4) | 0.22% | — | Knowledge BaseAI | 6/6/2025 | 17/6/2026 | The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kbalert' shortcode in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.44% | — | Openknowledgemaps HeadstartAI | 29/5/2025 | 17/6/2026 | An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component | |
| Aplazada | Crítica (9.8) | 0.41% | — | Public Knowledge Project OJSAIPublic Knowledge Project OMPAIPublic Knowledge Project OPSAI | 24/2/2025 | 17/6/2026 | In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin. | |
| Aplazada | Media (5.4) | 0.36% | — | Public Knowledge Project PKP PlatformAIPublic Knowledge Project OJSAIPublic Knowledge Project OMPAIPublic Knowledge Project OPSAI | 22/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Public Knowledge Project PKP Platform OJS/OMP/OPS- before v.3.3.0.16 allows an attacker to execute arbitrary code and escalate privileges via a crafted script | |
| Modificada | Media (5.4) | 0.24% | — | Webberzone Knowledge Base | 4/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Knowledge Base knowledgebase allows Stored XSS.This issue affects Knowledge Base: from n/a through <= 2.2.0. | |
| Aplazada | Media (6.1) | 0.48% | — | Public Knowledge Project Pkp-libAI | 21/10/2024 | 17/6/2026 | Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function. | |
| Analizada | Media (6.9) | 0.44% | — | Public Knowledge Project Open Journal Systems | 17/8/2024 | 17/6/2026 | A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login/signOut. The manipulation of the argument source with the input .example.com leads to open redirect. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.26% | — | SAP Netweaver Knowledge Management AND Collaboration (kmc-cm) | 9/7/2024 | 17/6/2026 | Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application but it has a low impact on its… |