Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
1090 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.23% | — | Magepeople Taxi Booking ManagerAI | 5/10/2026 | 6/10/2026 | Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.1.1. | |
| Aplazada | Media (6.5) | 0.24% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions. | |
| Aplazada | Media (5.4) | 0.17% | — | Magepeople WptravellyAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Magepeople inc. WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through 2.3.1. | |
| Aplazada | Alta (7.3) | 0.40% | — | Magepeople Taxi Booking Manager FOR WoocommerceAI | 22/9/2026 | 22/9/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8. | |
| Aplazada | Baja (2.1) | 0.37% | — | Omega Solution FBP Fulfillment BY PeopleAI | 21/9/2026 | 22/9/2026 | A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been… | |
| Pendiente de análisis | Alta (7.7) | 0.30% | — | Oracle Peoplesoft Enterprise PeopletoolsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | Oracle Peoplesoft Enterprise FIN Engineering BrazilAI | 15/9/2026 | 17/9/2026 | Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Engineering Brazil… | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Peoplesoft Enterprise FIN Inventory BrazilAI | 15/9/2026 | 17/9/2026 | Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Inventory Brazil executes… | |
| Pendiente de análisis | Alta (7.7) | 0.34% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUBAI | 15/9/2026 | 16/9/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: Enterprise Portal). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction… | |
| Pendiente de análisis | Alta (8.5) | 0.29% | — | Oracle Peoplesoft Enterprise PeopletoolsAI | 15/9/2026 | 16/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Oracle Peoplesoft Enterprise PeopletoolsAI | 15/9/2026 | 16/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Pendiente de análisis | Alta (7.3) | 0.32% | — | Oracle Peoplesoft Enterprise PeopletoolsAI | 15/9/2026 | 16/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks… | |
| Pendiente de análisis | Alta (8.1) | 0.37% | — | Oracle Peoplesoft Enterprise PeopletoolsAI | 15/9/2026 | 16/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Alta (8.1) | 0.42% | — | Oracle Peoplesoft Enterprise Peopletools | 15/9/2026 | 21/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Peoplesoft Enterprise Peopletools | 15/9/2026 | 21/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Peoplesoft Enterprise Peopletools | 15/9/2026 | 21/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Alta (7.2) | 0.14% | — | Oracle Peoplesoft Enterprise Peopletools | 15/9/2026 | 21/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise… | |
| Analizada | Alta (7) | 0.13% | — | Oracle Peoplesoft Enterprise Peopletools | 15/9/2026 | 21/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to… | |
| Analizada | Alta (8.1) | 0.38% | — | Oracle Peoplesoft Enterprise Peopletools | 15/9/2026 | 21/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Aplazada | Alta (8.6) | 0.45% | — | Codepeople Music StoreAI | 5/9/2026 | 8/9/2026 | The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | |
| Aplazada | Media (6.5) | 0.22% | — | Magepeople Booking AND Rental ManagerAI | 3/9/2026 | 3/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7. | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 18/8/2026 | 4/9/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects.… | |
| Analizada | Alta (7.5) | 0.13% | — | Oracle Peoplesoft Lease Administration | 18/8/2026 | 10/9/2026 | Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (component: Lease Administration). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Lease… | |
| En análisis | Alta (7.2) | 0.46% | — | Oracle Peoplesoft Enterprise FIN Common Objects BrazilAI | 18/8/2026 | 21/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.1. Easily exploitable vulnerability allows high privileged attacker with network access via T3, IIOP to compromise PeopleSoft Enterprise FIN Common… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Peoplesoft Enterprise CC Common Application Objects | 18/8/2026 | 4/9/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise PeopleSoft… |