Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.2)0.12%—Crmeb Knowledge-paid SystemAI21/9/20261/10/2026
CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information.
AplazadaAlta (7.1)0.25%—Knowledge Base FOR Documentation Faqs With AI AssistanceAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions.
AnalizadaMedia (5.4)0.23%—Oracle Knowledge Management21/7/202619/8/2026
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful…
AnalizadaMedia (6.1)0.13%—Oracle Knowledge Management21/7/202610/8/2026
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks…
AplazadaAlta (8.5)0.19%—Ipknowledge Musetheque V4AIIpknowledge V4l1AI15/5/202617/6/2026
Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected product, unexpected operations may be done.
AplazadaMedia (4.8)0.13%—Ipknowledge Musetheque V4AI15/5/202617/6/2026
Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script may be executed on a user's web browser when viewing the administration page showing the information of the file.
Pendiente de análisisCrítica (9.1)0.81%—Microsoft Asp.netAIMicrosoft IISAIDigital Knowledge KnowledgedeliverAI16/4/202617/6/2026
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks
AnalizadaMedia (4.4)0.15%—IBM Knowledge Catalog25/3/202617/6/2026
IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
AplazadaMedia (4.3)0.14%—ADD Google Social Profiles TO Knowledge Graph BOXAI21/3/202617/6/2026
The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's…
AplazadaMedia (4.3)0.19%—Echoplugins Knowledge Base FOR Documentation Faqs With AI AssistanceAI19/2/202617/6/2026
Missing Authorization vulnerability in echoplugins Knowledge Base for Documentation, FAQs with AI Assistance echo-knowledge-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through <= 16.011.0.
AplazadaMedia (6.5)0.17%—Basepress Knowledge Base Documentation & Wiki PluginAI31/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BasePress Knowledge Base documentation & wiki plugin – BasePress basepress allows Stored XSS.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through <= 2.17.0.1.
AplazadaMedia (6.5)0.19%—Xenioushk BWL Knowledge Base ManagerAI30/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Knowledge Base Manager bwl-kb-manager allows Stored XSS.This issue affects BWL Knowledge Base Manager: from n/a through <= 1.6.3.
AplazadaMedia (4.8)0.26%—Public Knowledge Project OMPAIPublic Knowledge Project OJSAI20/11/202517/6/2026
A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the argument manualInstructions leads to cross…
AplazadaAlta (8.8)0.53%—Designthemes Knowledge BaseAI22/10/202517/6/2026
Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9.
AplazadaMedia (4.4)0.26%—Knowledge BaseAI18/7/202517/6/2026
The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject…
AnalizadaCrítica (9.8)0.72%—Mmz-001 Knowledgegpt24/6/202517/6/2026
An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.
AplazadaAlta (7.1)0.13%—Devfelixmoira Knowledge Base MakerAI20/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base – Knowledge Base Maker knowledge-base-maker allows Stored XSS.This issue affects Knowledge Base – Knowledge Base Maker: from n/a through <= 1.1.8.
AplazadaMedia (6.4)0.22%—Knowledge BaseAI6/6/202517/6/2026
The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kbalert' shortcode in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.8)0.44%—Openknowledgemaps HeadstartAI29/5/202517/6/2026
An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component
AplazadaCrítica (9.8)0.41%—Public Knowledge Project OJSAIPublic Knowledge Project OMPAIPublic Knowledge Project OPSAI24/2/202517/6/2026
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.
AplazadaMedia (5.4)0.36%—Public Knowledge Project PKP PlatformAIPublic Knowledge Project OJSAIPublic Knowledge Project OMPAIPublic Knowledge Project OPSAI22/11/202417/6/2026
Cross Site Scripting vulnerability in Public Knowledge Project PKP Platform OJS/OMP/OPS- before v.3.3.0.16 allows an attacker to execute arbitrary code and escalate privileges via a crafted script
ModificadaMedia (5.4)0.24%—Webberzone Knowledge Base4/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Knowledge Base knowledgebase allows Stored XSS.This issue affects Knowledge Base: from n/a through <= 2.2.0.
AplazadaMedia (6.1)0.48%—Public Knowledge Project Pkp-libAI21/10/202417/6/2026
Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function.
AnalizadaMedia (6.9)0.44%—Public Knowledge Project Open Journal Systems17/8/202417/6/2026
A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login/signOut. The manipulation of the argument source with the input .example.com leads to open redirect. The attack may be launched remotely. The exploit has been…
ModificadaMedia (6.1)0.26%—SAP Netweaver Knowledge Management AND Collaboration (kmc-cm)9/7/202417/6/2026
Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application but it has a low impact on its…