Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Siebel Apps Self ServiceAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Self Service. Successful attacks of… | |
| Aplazada | Media (5.9) | 1.1% | — | Sage Employee Self ServiceAI | 1/9/2026 | 9/9/2026 | A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants, an attacker may bypass directory restrictions and access files outside the application's intended… | |
| Pendiente de análisis | Crítica (9.3) | 0.36% | — | Oracle Siebel Apps - Self ServiceAI | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Self Service. Successful attacks… | |
| Analizada | Media (6.5) | 0.39% | — | Oracle Self-service Human Resources | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Manager Self-Service). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Self-service Human Resources | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human… | |
| Aplazada | Media (5.1) | 0.34% | — | Ellucian Banner Self-serviceAI | 9/6/2026 | 23/7/2026 | Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerability in the course search functionality that allows authenticated Banner ERP users to inject malicious payloads into faculty and course fields by exploiting missing HTML encoding during DOM insertion.… | |
| Aplazada | Media (5.1) | 0.36% | — | Ellucian Banner Self-serviceAI | 9/6/2026 | 23/7/2026 | Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting unsanitized input through the toDateFormat request parameter in the dateConverter… | |
| Aplazada | Baja (2.1) | 0.19% | — | Tiobon Employee Self-service SystemAI | 7/6/2026 | 23/7/2026 | A vulnerability was found in Tiobon Employee Self-Service System up to 7.2. Affected by this vulnerability is an unknown functionality of the file /Blog/BlogSearch.aspx of the component Login Endpoint. The manipulation of the argument Keyword results in sql injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Media (5.5) | 2.9% | — | Tosei Self-service Washing MachineAI | 16/2/2026 | 17/6/2026 | A flaw has been found in Tosei Self-service Washing Machine 4.02. Impacted is an unknown function of the file /cgi-bin/tosei_datasend.php. Executing a manipulation of the argument adr_txt_1 can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The… | |
| Aplazada | Alta (8.6) | 0.41% | — | Ltb-project Self Service PasswordAI | 19/12/2025 | 17/6/2026 | LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting… | |
| Aplazada | Alta (7.3) | 0.34% | — | Opentext Self Service Password ResetAI | 29/8/2025 | 17/6/2026 | Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Authentication Bypass.This issue affects Self Service Password Reset from before 4.8 patch 3. | |
| Analizada | Media (6.5) | 0.41% | — | Onespan Vasco Self-service Portal | 21/5/2025 | 17/6/2026 | Local File Inclusion vulnerability in Vasco v3.14and before allows a remote attacker to obtain sensitive information via help menu. | |
| Analizada | Media (6.1) | 0.32% | — | Microfocus Netiq Self Service Password Reset | 21/8/2024 | 17/6/2026 | Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Cross-Site Scripting (XSS). This issue affects Self Service Password Reset before 4.5.0.2 and 4.4.0.6 | |
| Modificada | Crítica (9.8) | 1.2% | — | Ltb-project Self Service Password | 21/12/2023 | 17/6/2026 | An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary phone. | |
| Modificada | Media (4.3) | 0.45% | — | Oracle Self-service Human Resources | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Workforce Management). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human… | |
| Modificada | Media (6.1) | 0.52% | — | Pingidentity Self-service Account Manager | 10/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2. Affected by this issue is some unknown functionality of the file src/main/java/com/unboundid/webapp/ssam/SSAMController.java. The manipulation leads to cross site scripting. The attack may be… | |
| Modificada | Media (4.3) | 0.45% | — | Oracle Self-service Human Resources | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Workflow, Approval, Work Force Management). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (4.3) | 0.76% | — | SAP Employee Self Service | 11/5/2022 | 17/6/2026 | Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other users causing a limited impact on confidentiality of the application. | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Self Service Password Reset | 5/11/2020 | 17/6/2026 | Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information. | |
| Modificada | Alta (8.4) | 1.2% | — | Hcltech Self-service Application | 28/2/2020 | 17/6/2026 | BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Running Message or Post Message HTML. | |
| Modificada | Media (5.9) | 0.40% | — | Microfocus Netiq Self Service Password Reset | 22/10/2019 | 17/6/2026 | Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack. | |
| Modificada | Crítica (9.8) | 2.1% | — | Microfocus Netiq Self Service Password Reset | 14/8/2019 | 17/6/2026 | A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. Upgrade to Micro Focus Self Service Password Reset (SSPR) SSPR versions 4.4.0.3, 4.3.0.6, or 4.2.0.6 as appropriate. | |
| Modificada | Alta (7.5) | 1.1% | — | Netiq Self Service Password Reset | 24/6/2019 | 17/6/2026 | An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be exploited to expose sensitive information. | |
| Modificada | Media (6.1) | 0.65% | — | Microfocus Netiq Self Service Password Reset | 24/6/2019 | 17/6/2026 | A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack. | |
| Modificada | Alta (7.5) | 0.78% | — | Jamf Self Service | 25/2/2019 | 17/6/2026 | Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell scripts" feature to insert "/Applications/Utilities/Terminal app/Contents/MacOS/Terminal" into the TCP data stream. |