Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
375 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.0% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 18/7/2018 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. Cisco Bug IDs: CSCvg70921. | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 18/7/2018 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967. | |
| Modificada | Media (6.1) | 1.3% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 18/7/2018 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904. | |
| Modificada | Alta (7.5) | 1.1% | — | Cibnliveinteractive Project Cibnliveinteractive | 5/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for CIBN Live Token (CIBN LIVE), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (8.1) | 2.3% | — | Interactivebrokers Ibapi | 29/5/2018 | 17/6/2026 | ibapi is an Interactive Brokers API addon for NodeJS. ibapi downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. Before 2.5.6, it may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: EPPCM_HIER_TOP). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL… | |
| Modificada | Alta (7.8) | 0.38% | — | Schneider-electric Interactive Graphical Scada System | 12/2/2018 | 17/6/2026 | A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security. | |
| Modificada | Media (6.1) | 30% | 💥 PoC | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 19/10/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Enterprise Portal). The supported version that is affected is 9.1.00. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 19/10/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Enterprise Portal). The supported version that is affected is 9.1.00. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Interaction Center Intelligence | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Interaction Center Intelligence component of Oracle E-Business Suite (subcomponent: Setup). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Interaction… | |
| Modificada | Media (6.1) | 1.2% | — | Qodeinteractive Bridge | 23/8/2017 | 17/6/2026 | DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers to inject arbitrary JavaScript. | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 8/8/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Add New Image). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 8/8/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Browse Folder Hierarchy). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 8/8/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: EPPCM_HIER_TOP). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 8/8/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: EPPCM_HIER_TOP). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 8/8/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: EPPCM_HIER_TOP). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 8/8/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: HTML Area). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 8/8/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: EPPCM_DEFN_CATG). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 8/8/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: HTML Area). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 8/8/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: HTML Area). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 8/8/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Maintenance Folders). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (5.4) | 1.0% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 8/8/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Discussion Forum). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Alta (8.8) | 0.45% | — | IBM Interact | 10/5/2017 | 17/6/2026 | IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 115085. | |
| Modificada | Media (5.4) | 0.51% | — | IBM Interact | 10/5/2017 | 17/6/2026 | IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 115084. |