Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
323 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.6) | 1.4% | — | Oracle Business Intelligence Publisher | 8/8/2017 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. Successful attacks… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Business Intelligence Publisher | 8/8/2017 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Business Intelligence Publisher | 8/8/2017 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Business Intelligence Publisher | 8/8/2017 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Business Intelligence Publisher | 8/8/2017 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human… | |
| Modificada | Alta (8.2) | 2.1% | — | Oracle Business Intelligence Publisher | 8/8/2017 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks of this… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Business Intelligence Publisher | 8/8/2017 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Layout Tools). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human… | |
| Modificada | Alta (7.8) | 0.40% | — | Flexerasoftware Flexnet Publisher | 15/6/2017 | 17/6/2026 | In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the FlexNet Publisher Licensing Service can be exploited to cause an out-of-bounds memory read access and subsequently execute arbitrary code with… | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Media (6.1) | 1.8% | — | Flexerasoftware Flexnet Publisher | 3/3/2017 | 17/6/2026 | Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and the Citrix License Server VPX, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified… | |
| Modificada | Alta (7.8) | 25% | — | Microsoft Publisher | 20/12/2016 | 17/6/2026 | Microsoft Publisher 2010 SP2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." | |
| Modificada | Alta (7.7) | 14% | 💥 Exploit | Oracle Business Intelligence Publisher | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors. | |
| Modificada | Baja (3.7) | 1.9% | — | Oracle Business Intelligence Publisher | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality via vectors related to Security. | |
| Modificada | Media (5.4) | 1.2% | — | Oracle Business Intelligence Publisher | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to Web Server. | |
| Modificada | Crítica (9.8) | 29% | 💥 PoC | Flexerasoftware Flexnet Publisher | 24/2/2016 | 17/6/2026 | Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote attackers to execute arbitrary code via a crafted packet with opcode (a) 0x107 or (b) 0x10a. | |
| Modificada | Media (4) | 1.4% | — | Oracle Business Intelligence Publisher | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors. | |
| Modificada | Alta (9.3) | 17% | — | Microsoft AccessMicrosoft ExcelMicrosoft InfopathMicrosoft Lync+10 | 11/11/2015 | 17/6/2026 | Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2007 IME (Japanese) SP3, Access 2010 SP2, Excel 2010 SP2, InfoPath 2010 SP2, OneNote 2010 SP2, PowerPoint 2010 SP2, Project 2010 SP2,… | |
| Modificada | Media (6.8) | 0.58% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 20/8/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in EMC Documentum WebTop before 6.8P01, Documentum Administrator through 7.2, Documentum Digital Assets Manager through 6.5SP6, Documentum Web Publishers through 6.5SP7, and Documentum Task Space through 6.7SP2 allows remote attackers to hijack the authentication of… | |
| Modificada | Alta (7.5) | 13% | 💥 PoC | Apache ActivemqOracle Business Intelligence PublisherOracle Fusion Middleware | 14/8/2015 | 17/6/2026 | The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command. | |
| Modificada | Media (5.8) | 1.8% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 16/7/2015 | 17/6/2026 | Open redirect vulnerability in EMC Documentum WebTop before 6.8P02, Documentum Administrator before 7.2P01, Documentum Digital Assets Manager through 6.5SP6, Documentum Web Publishers through 6.5SP7, and Documentum Task Space through 6.7SP2 allows remote attackers to redirect users to arbitrary web sites and conduct… | |
| Modificada | Media (6.5) | 2.4% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 4/7/2015 | 17/6/2026 | Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5… | |
| Modificada | Baja (3.5) | 1.1% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 4/7/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web… | |
| Modificada | Baja (3.5) | 0.95% | — | Drupal Doubleclick FOR Publishers | 13/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission to inject arbitrary web script or HTML via a slot name. | |
| Modificada | Media (6.8) | 0.98% | — | EMC Digital Assets ManagerEMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum Records Manager+5 | 20/8/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Media (4.3) | 1.8% | — | EMC Digital Assets ManagerEMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum Webtop+4 | 20/8/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter. |