Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 30% | 💥 PoC | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Alta (8.1) | 1.5% | — | Oracle Primavera Unifier | 18/1/2018 | 17/6/2026 | Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Platform). Supported versions that are affected are 10.x, 15.x, 16.x and 17.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier.… | |
| Modificada | Alta (7.8) | 0.58% | — | CiphershedIdrix VeracryptTruecrypt | 3/10/2017 | 17/6/2026 | The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation level of impersonation tokens, which allows local users to impersonate a user at SecurityIdentify level and gain access to… | |
| Modificada | Alta (7.8) | 1.2% | 💥 Exploit | CiphershedIdrix VeracryptTruecrypt | 3/10/2017 | 17/6/2026 | The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted volume over an existing drive letter and gain privileges via an entry in the… | |
| Modificada | Media (4.3) | 1.4% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP… | |
| Modificada | Media (4.3) | 1.3% | — | Oracle Primavera Unifier | 8/8/2017 | 17/6/2026 | Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions that are affected are 9.13, 9.14, 10.1, 10.2, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera… | |
| Modificada | Media (4.8) | 1.0% | — | Oracle Primavera Unifier | 8/8/2017 | 17/6/2026 | Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions that are affected are 9.13, 9.14, 10.1, 10.2, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera… | |
| Modificada | Media (6.5) | 1.0% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP… | |
| Modificada | Media (5.4) | 3.9% | 💥 Exploit | Oracle Primavera P6 Enterprise Project Portfolio Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and 16.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.5) | 1.9% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Alta (8.1) | 2.1% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 24/4/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 24/4/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Crítica (9.1) | 2.3% | — | Oracle Primavera Gateway | 24/4/2017 | 17/6/2026 | Vulnerability in the Primavera Gateway component of Oracle Primavera Products Suite (subcomponent: Primavera Desktop Integration). Supported versions that are affected are 1.0, 1.1, 14.2, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerability allows high privileged attacker with network access via HTTP to… | |
| Modificada | Crítica (9.9) | 2.1% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 24/4/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access (Apache Commons BeanUtils)). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerability allows low privileged attacker… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Primavera Unifier | 24/4/2017 | 17/6/2026 | Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions that are affected are 9.13, 9.14, 10.0, 10.1, 15.1 and 15.2. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.… | |
| Modificada | Alta (8.7) | 2.0% | — | Oracle Primavera Gateway | 24/4/2017 | 17/6/2026 | Vulnerability in the Primavera Gateway component of Oracle Primavera Products Suite (subcomponent: Primavera Desktop Integration). Supported versions that are affected are 1.0, 1.1, 14.2, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerability allows high privileged attacker with network access via HTTP to… | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Media (6.1) | 23% | — | Jqueryui Jquery UIOracle Application ExpressOracle Business IntelligenceOracle Hospitality Cruise Fleet Management+9 | 15/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function. | |
| Modificada | Media (6.2) | 1.0% | — | Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware | 5/2/2017 | 17/6/2026 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective. | |
| Modificada | Alta (7.5) | 1.8% | — | Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware | 5/2/2017 | 17/6/2026 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. The application failed to check the access control of the request which could result in an attacker being able to shutdown the system. | |
| Modificada | Crítica (9.8) | 2.4% | — | Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware | 5/2/2017 | 17/6/2026 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands. | |
| Modificada | Crítica (10) | 2.0% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 27/1/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.2, 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Alta (8.1) | 1.3% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 27/1/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Team Member). Supported versions that are affected are 8.2, 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via… | |
| Modificada | Media (6.5) | 9.9% | — | Momentjs MomentTenable NessusOracle Primavera Unifier | 23/1/2017 | 17/6/2026 | The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)." | |
| Modificada | Alta (7.8) | 0.82% | — | Idrix TruecryptIdrix Veracrypt | 23/1/2017 | 17/6/2026 | Untrusted search path vulnerability in the installer for TrueCrypt 7.2 and 7.1a, VeraCrypt before 1.17-BETA, and possibly other products allows local users to execute arbitrary code with administrator privileges and conduct DLL hijacking attacks via a Trojan horse DLL in the "application directory", as demonstrated… |