Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
168 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.30% | — | Paidmembershipsincorporated Paid Memberships SubscriptionsAI | 17/9/2026 | 18/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount. | |
| Aplazada | Alta (7.1) | 0.27% | — | Oracle Banking Corporate Lending Process ManagementAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Aplazada | Alta (8) | 0.20% | — | Oracle Banking Corporate LendingAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the… | |
| Aplazada | Alta (8.8) | 0.24% | — | Memberpress Corporate AccountsAI | 12/9/2026 | 14/9/2026 | The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like… | |
| Aplazada | Crítica (9.3) | 0.65% | — | Sunnet Corporate Training Management SystemAI | 24/7/2026 | 28/7/2026 | An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a… | |
| Aplazada | Media (4.3) | 0.28% | — | Gobito Informatics Technologies Corporate Training Management SystemAI | 20/7/2026 | 21/7/2026 | Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This issue affects Corporate Training Management System: before dd1a9df64. | |
| Aplazada | Alta (8.1) | 0.47% | — | Pearl Corporate BusinessAI | 2/7/2026 | 2/7/2026 | Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions. | |
| Aplazada | Alta (8.5) | 0.14% | — | PDF Complete Corporate EditionAI | 23/1/2026 | 17/6/2026 | PDF Complete Corporate Edition 4.1.45 contains an unquoted service path vulnerability in the pdfcDispatcher service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service binary location to inject malicious executables that will be run with elevated… | |
| Aplazada | Alta (7.3) | 0.25% | — | Divvydrive Information Technologies INC Digital Corporate WarehouseAI | 12/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive Information Technologies Inc. Digital Corporate Warehouse allows Stored XSS. This issue affects Digital Corporate Warehouse: before v.4.8.2.22. | |
| Aplazada | Media (5.3) | 0.29% | — | Vimesoft Information Technologies AND Software Vimesoft Corporate Messaging PlatformAI | 26/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. Vimesoft Corporate Messaging Platform allows Retrieve Embedded Sensitive Data. This issue affects Vimesoft Corporate Messaging Platform: from V1.3.0 before V2.0.0. | |
| Aplazada | Media (4.3) | 0.24% | — | Priyanshumittal SHK CorporateAI | 5/9/2025 | 17/6/2026 | Missing Authorization vulnerability in priyanshumittal Shk Corporate shk-corporate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shk Corporate: from n/a through <= 2.4.1.1. | |
| Analizada | Media (6.4) | 0.21% | — | Corporatezen Responsive Food AND Drink Menu | 26/6/2025 | 17/6/2026 | The Responsive Food and Drink Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_pdf_menus shortcode in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.1) | 1.0% | — | Stylemixthemes Pearl Corporate BusinessAI | 26/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Pearl - Corporate Business pearl allows PHP Local File Inclusion.This issue affects Pearl - Corporate Business: from n/a through < 3.4.8. | |
| Aplazada | Crítica (9.4) | 0.76% | — | Corporate Training Management SystemAI | 19/12/2024 | 17/6/2026 | A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file. | |
| Aplazada | Alta (8.6) | 0.63% | — | Corporatezen222 Contact Page With Google MAPAI | 20/11/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in corporatezen222 Contact Page With Google Map contact-page-with-google-map allows Path Traversal.This issue affects Contact Page With Google Map: from n/a through <= 1.6.1. | |
| Modificada | Crítica (9.8) | 0.42% | — | Uni-yaz Flexwater Corporate Water Management | 18/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc. FlexWater Corporate Water Management allows SQL Injection. This issue affects FlexWater Corporate Water Management: before 5.452.0. | |
| Aplazada | Crítica (10) | 0.42% | — | Vadi Corporate Information Systems Digikent GISAI | 30/5/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vadi Corporate Information Systems DIGIKENT GIS allows SQL Injection. This issue affects DIGIKENT GIS: through 2.23.5. | |
| Aplazada | Media (6.5) | 0.36% | — | Looking Forward Software Incorporated Popup BuilderAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Looking Forward Software Incorporated. Popup Builder allows Stored XSS.This issue affects Popup Builder: from n/a through 4.2.6. | |
| Modificada | Alta (7.8) | 0.35% | — | Univention Corporate Server | 31/10/2023 | 17/6/2026 | The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to gain higher privileges and perform followup attacks. By default, the configuration of UCS does not… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+24 | 1/4/2022 | 17/6/2026 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. | |
| Modificada | Media (5.5) | 3.1% | — | Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+3 | 12/6/2021 | 17/6/2026 | In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. | |
| Modificada | Media (5.5) | 3.4% | — | Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+8 | 12/6/2021 | 17/6/2026 | In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. | |
| Modificada | Alta (8.8) | 77% | 💥 Exploit | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+13 | 28/5/2021 | 7/10/2026 | XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's… | |
| Modificada | Media (5.9) | 4.9% | — | NettyDebian LinuxNetapp Oncommand API ServicesNetapp Oncommand Workflow Automation+14 | 30/3/2021 | 17/6/2026 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not… | |
| Modificada | Media (5.5) | 3.3% | — | Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+15 | 19/3/2021 | 17/6/2026 | A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. |