Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
375 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 1.6% | — | Oracle Customer Interaction History | 24/4/2017 | 17/6/2026 | Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: Admin Console). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer… | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Alta (7.8) | 1.3% | — | Schneider-electric Interactive Graphical Scada System | 7/4/2017 | 17/6/2026 | A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path. | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa | Apache TomcatCanonical Ubuntu LinuxNetapp 7-mode Transition ToolNetapp Oncommand Insight+15 | 6/4/2017 | 25/8/2026 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427… | |
| Modificada | Alta (8.2) | 1.4% | — | Oracle Customer Interaction History | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Customer Interaction History | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer… | |
| Modificada | Alta (8.2) | 1.8% | — | Oracle Customer Interaction History | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer… | |
| Modificada | Alta (8.2) | 1.5% | — | Oracle Interaction Blending | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Interaction Blending component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Customer Interaction History | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5592. | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Customer Interaction History | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5587 and CVE-2016-5591. | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Customer Interaction History | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5595. | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Customer Interaction History | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5587 and CVE-2016-5593. | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Customer Interaction History | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5591 and CVE-2016-5593. | |
| Modificada | Media (6.5) | 1.6% | — | Oracle Interaction Center Intelligence | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Interaction Center Intelligence component in Oracle E-Business Suite 12.1.1 through 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Alta (8.2) | 2.7% | — | Oracle Customer Interaction History | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Function Security. | |
| Modificada | Media (6.4) | 1.7% | — | Oracle Interaction Center Intelligence | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Interaction Center Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Business Intelligence. | |
| Modificada | Media (6.4) | 1.8% | — | Oracle Customer Interaction History | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0527, CVE-2016-0528, and… | |
| Modificada | Media (6.4) | 1.8% | — | Oracle Customer Interaction History | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0527, CVE-2016-0528, and… | |
| Modificada | Media (5.5) | 1.4% | — | Oracle Interaction Blending | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Interaction Blending component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Blending Administration. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Unified WEB AND E-mail Interaction Manager | 14/12/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Unified Email Interaction Manager and Unified Web Interaction Manager 11.0(1) allows remote attackers to inject arbitrary web script or HTML a crafted URL, aka Bug ID CSCuw24479. | |
| Modificada | Media (4.3) | 2.3% | — | Cisco Unified WEB AND E-mail Interaction Manager | 19/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Unified Web and E-Mail Interaction Manager 9.0(2) allows remote attackers to inject arbitrary web script or HTML via a crafted chat message, aka Bug ID CSCuo89051. | |
| Modificada | Media (5.5) | 2.5% | — | Cisco Unified WEB AND E-mail Interaction Manager | 19/8/2015 | 17/6/2026 | Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default messaging-queue system folders via unspecified vectors, aka Bug ID CSCuo89046. | |
| Modificada | Media (6.5) | 2.5% | — | Cisco Unified WEB AND E-mail Interaction Manager | 19/8/2015 | 17/6/2026 | Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056. | |
| Modificada | Media (6.8) | 1.8% | — | Cisco Unified WEB AND E-mail Interaction Manager | 29/5/2015 | 17/6/2026 | SQL injection vulnerability in Cisco Unified Email Interaction Manager (EIM) and Unified Web Interaction Manager (WIM) 9.0(2) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuu30028. | |
| Modificada | Media (4.3) | 1.2% | — | Levelteninteractive Content Analysis | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Content Analysis module before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a log message. |