Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (10) | 6.8% | — | Apache Commons ConfigurationOracle Database ServerOracle Healthcare Foundation | 13/3/2020 | 17/6/2026 | Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from… | |
| Modificada | Alta (7.8) | 0.57% | — | Debian X11-commonDebian Linux | 21/2/2020 | 16/6/2026 | The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation. | |
| Modificada | Media (5.3) | 1.4% | — | Oracle Peoplesoft Enterprise Cost Center Common Application Objects | 15/1/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Approval Framework). Supported versions that are affected are 9.1 and 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (6.1) | 0.78% | — | Netcommons | 26/12/2019 | 17/6/2026 | Cross-site scripting vulnerability in NetCommons 3.2.2 and earlier (NetCommons3.x) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.50% | — | Postgresql-commonCanonical Ubuntu LinuxDebian Linux | 20/11/2019 | 17/6/2026 | The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation. | |
| Modificada | Alta (7.5) | 16% | — | Apache Commons CompressFedoraproject FedoraOracle Banking PaymentsOracle Banking Platform+15 | 30/8/2019 | 17/6/2026 | The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress. | |
| Modificada | Crítica (9.8) | 1.4% | — | Xm-online Xm^online 2 - Common Utils AND Endpoints | 26/8/2019 | 17/6/2026 | XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java. | |
| Modificada | Alta (7.3) | 28% | — | Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+56 | 20/8/2019 | 25/8/2026 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | |
| Modificada | Media (4.2) | 1.2% | — | Oracle Siebel Core - Common Components | 23/7/2019 | 17/6/2026 | Vulnerability in the Siebel Core - Common Components component of Oracle Siebel CRM (subcomponent: Email). Supported versions that are affected are 19.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel Core - Common Components. Successful… | |
| Modificada | Alta (7.5) | 1.9% | — | Apache Commons Imaging | 6/5/2019 | 17/6/2026 | Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note that Apache Sanselan (incubating) was renamed to Apache Commons Imaging. | |
| Modificada | Alta (7.5) | 1.9% | — | Apache Commons Imaging | 6/5/2019 | 17/6/2026 | Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note that Apache Sanselan (incubating) was renamed to Apache Commons Imaging. | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Common Applications | 23/4/2019 | 17/6/2026 | Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: CRM User Management Framework). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access… | |
| Modificada | Media (6.6) | 1.2% | — | Omron Common ComponentsOmron Cx-programmer | 10/4/2019 | 17/6/2026 | When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 and prior) fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application. | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins Hyper.sh Commons | 4/4/2019 | 17/6/2026 | Jenkins Hyper.sh Commons Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Media (6.1) | 1.1% | — | Thephpleague Commonmark | 24/3/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML entities that are not properly escaped during rendering, a different vulnerability than CVE-2018-20583. | |
| Modificada | Crítica (9.8) | 5.8% | — | Cisco Common Services Platform Collector | 13/3/2019 | 17/6/2026 | A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device by using an account that has a default, static password. This account does not have administrator privileges. The vulnerability exists because the affected software has a… | |
| Modificada | Media (5.4) | 0.76% | — | Oracle Peoplesoft Enterprise Cost Center Common Application Objects | 16/1/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects component of Oracle PeopleSoft Products (subcomponent: Form and Approval Builder). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.1) | 1.6% | — | Thephpleague Commonmark | 30/12/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., writing javascript as javascri%0apt). | |
| Modificada | Crítica (9.8) | 2.4% | — | Bosch Common Product Platform 4 FirmwareBosch Common Product Platform 6 FirmwareBosch Common Product Platform 7 FirmwareBosch Common Product Platform 7.3 Firmware | 17/12/2018 | 17/6/2026 | An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface. | |
| Modificada | Media (6.1) | 1.6% | — | Oracle Hyperion Common Events | 17/10/2018 | 17/6/2026 | Vulnerability in the Hyperion Common Events component of Oracle Hyperion (subcomponent: User Interface). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Common Events. Successful attacks require… | |
| Modificada | Media (6.1) | 1.6% | — | Oracle Hyperion Common Events | 17/10/2018 | 17/6/2026 | Vulnerability in the Hyperion Common Events component of Oracle Hyperion (subcomponent: User Interface). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Common Events. Successful attacks require… | |
| Modificada | Media (6.1) | 1.6% | — | Oracle Hyperion Common Events | 17/10/2018 | 17/6/2026 | Vulnerability in the Hyperion Common Events component of Oracle Hyperion (subcomponent: User Interface). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Common Events. Successful attacks require… | |
| Modificada | Media (6.1) | 1.6% | — | Oracle Hyperion Common Events | 17/10/2018 | 17/6/2026 | Vulnerability in the Hyperion Common Events component of Oracle Hyperion (subcomponent: User Interface). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Common Events. Successful attacks require… | |
| Modificada | Media (5.5) | 0.43% | — | LibxkbcommonXkbcommonCanonical Ubuntu Linux | 25/8/2018 | 17/6/2026 | Unchecked NULL pointer usage in resolve_keysym in xkbcomp/parser.y in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because a map access attempt can occur for a map that was never created. | |
| Modificada | Media (5.5) | 0.54% | — | LibxkbcommonXkbcommonCanonical Ubuntu Linux | 25/8/2018 | 17/6/2026 | Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file with a no-op modmask expression. |