Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.3% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 27/1/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Team Member). Supported versions that are affected are 8.2, 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via… | |
| Modificada | Media (5.4) | 0.90% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.4, 15.x, and 16.x allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Alta (7.2) | 2.1% | — | Huge-it Portfolio Gallery Manager | 21/10/2016 | 17/6/2026 | Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS | |
| Modificada | Alta (7.2) | 2.9% | — | Huge-it Portfolio Gallery Manager | 21/10/2016 | 17/6/2026 | Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS | |
| Modificada | Crítica (9.8) | 2.5% | 💥 Exploit | Huge-it Portfolio Gallery | 6/10/2016 | 17/6/2026 | Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6 | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote attackers to affect confidentiality and integrity via vectors related to Web access, a different vulnerability than CVE-2016-3566,… | |
| Modificada | Media (6.4) | 1.4% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote authenticated users to affect confidentiality and integrity via vectors related to Web Access. | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote attackers to affect confidentiality and integrity via vectors related to Web access, a different vulnerability than CVE-2016-3566,… | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote attackers to affect confidentiality and integrity via vectors related to Web access, a different vulnerability than CVE-2016-3566,… | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote attackers to affect confidentiality and integrity via vectors related to Web access, a different vulnerability than CVE-2016-3566,… | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote attackers to affect confidentiality and integrity via vectors related to Web access, a different vulnerability than CVE-2016-3566,… | |
| Modificada | Media (5.4) | 1.2% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote authenticated users to affect confidentiality and integrity via vectors related to Web access. | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote attackers to affect confidentiality and integrity via vectors related to Web access, a different vulnerability than CVE-2016-3568,… | |
| Modificada | Alta (8.8) | 5.1% | — | Oracle DocumakerOracle Enterprise Manager OPS CenterOracle Health Sciences Information ManagerOracle Healthcare Master Person Index+7 | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index… | |
| Modificada | Alta (8.8) | 2.3% | — | HPE Project AND Portfolio Management Center | 9/6/2016 | 17/6/2026 | HPE Project and Portfolio Management Center (PPM) 9.2x and 9.3x before 9.32.0002 allows remote authenticated users to execute arbitrary commands or obtain sensitive information via unspecified vectors. | |
| Modificada | Baja (3.5) | 1.2% | — | Ghozylab Gallery - Photo Albums - Portfolio | 28/9/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in includes/metaboxes.php in the Gallery - Photo Albums - Portfolio plugin 1.3.47 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) Media Title or (2) Media Subtitle fields. | |
| Modificada | Media (6.8) | 1.2% | — | Portfolio Project Portfolio | 19/8/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Portfolio plugin before 1.05 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the instagram-portfolio page in wp-admin/options-general.php. | |
| Modificada | Media (4) | 1.4% | — | IBM Emptoris Sourcing PortfolioIBM Emptoris Program ManagementIBM Emptoris Contract ManagementIBM Emptoris | 10/1/2015 | 17/6/2026 | The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x before 10.0.1.5 iFix2, and 10.0.2.x before 10.0.2.2 iFix5; Emptoris Sourcing 9.5 before 9.5.1.3 iFix2, 10.0.0.x before 10.0.0.1 iFix1, 10.0.1.x before 10.0.1.3 iFix1, and 10.0.2.x before 10.0.2.5;… | |
| Modificada | Media (5.4) | 0.27% | — | Andsocialrew Amkamal Science Portfolio | 21/10/2014 | 17/6/2026 | The AMKAMAL Science Portfolio (aka com.wAMKAMALSciencePortfolio) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Cnnmoney Portfolio FOR Stocks | 2/10/2014 | 17/6/2026 | The CNNMoney Portfolio for stocks (aka com.cnn.portfolio) application 1.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Cnnmoney Portfolio | 11/9/2014 | 17/6/2026 | The CNNMoney Portfolio (aka com.cnn.cnnmoney) application 1.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.9) | 0.80% | — | IBM Emptoris Spend AnalysisIBM Emptoris Sourcing Portfolio | 26/8/2014 | 17/6/2026 | IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 and Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 do not properly restrict use of FRAME elements, which allows remote… | |
| Modificada | Media (6) | 0.85% | — | IBM Emptoris Spend AnalysisIBM Emptoris Sourcing PortfolioIBM Emptoris Contract Management | 26/8/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2; Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and… | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Emptoris Sourcing Portfolio | 26/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.4) | 31% | 💥 Exploit | Oracle Database ServerOracle Primavera P6 Enterprise Project Portfolio Management | 21/9/2012 | 16/6/2026 | The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks,… |