Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 2.2% | — | Oracle Peoplesoft Enterprise Peopletools | 18/7/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.55 and 8.56. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Peopletools | 18/7/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Workflow). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Peopletools | 18/7/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Workflow). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Media (6.5) | 2.4% | — | Oracle Peoplesoft Enterprise Peopletools | 18/7/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (4.3) | 1.1% | — | Oracle Peoplesoft Enterprise Peopletools | 18/7/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Search Functionality). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft… | |
| Modificada | Media (6.2) | 0.52% | — | Oracle Peoplesoft Enterprise Peopletools | 18/7/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Configuration Manager). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Peopletools | 18/7/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Peopletools | 18/7/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Unified Navigation). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Crítica (9.8) | 4.8% | — | Bouncycastle Bc-javaNetapp Oncommand Workflow AutomationOpensuse LeapOracle API Gateway+20 | 9/7/2018 | 17/6/2026 | Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an… | |
| Modificada | Alta (7.5) | 3.6% | — | Bouncycastle Bc-javaBouncycastle Fips Java APIDebian LinuxOracle API Gateway+16 | 5/6/2018 | 17/6/2026 | Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA… | |
| Modificada | Crítica (9.1) | 5.9% | — | Debian LinuxCanonical Ubuntu LinuxHaxx CurlRedhat Enterprise Linux Desktop+5 | 24/5/2018 | 17/6/2026 | curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl <… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Peoplesoft Enterprise Peopletools | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Rich Text Editor). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft… | |
| Modificada | Media (4.3) | 1.4% | — | Oracle Peoplesoft Enterprise Peopletools | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Core). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (4.3) | 1.7% | — | Oracle Peoplesoft Enterprise Peopletools | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Homepage & Navigation). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.2) | 0.49% | — | Oracle Peoplesoft Enterprise PT Peopletools | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: PsAdmin). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PT… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Peoplesoft Enterprise Peopletools | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Core). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (4.7) | 1.7% | — | Oracle Peoplesoft Enterprise Peopletools | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Stylesheet). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Alta (7.3) | 1.8% | — | Oracle Peoplesoft Enterprise Peopletools | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: SQR). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT… | |
| Modificada | Alta (8.8) | 2.3% | — | Oracle Peoplesoft Enterprise Peopletools | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Rich Text Editor). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Crítica (9.1) | 9.0% | — | Debian LinuxCanonical Ubuntu LinuxHaxx CurlRedhat Enterprise Linux Desktop+5 | 14/3/2018 | 17/6/2026 | A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage | |
| Modificada | Alta (7.5) | 9.2% | — | Debian LinuxCanonical Ubuntu LinuxHaxx CurlRedhat Enterprise Linux Desktop+5 | 14/3/2018 | 17/6/2026 | A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service | |
| Modificada | Crítica (9.8) | 12% | — | Debian LinuxCanonical Ubuntu LinuxHaxx CurlRedhat Enterprise Linux Desktop+5 | 14/3/2018 | 17/6/2026 | A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse. | |
| Modificada | Media (6.1) | 30% | 💥 PoC | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Media (6.5) | 1.5% | — | Oracle Peoplesoft Enterprise Peopletools | 18/1/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Query). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (5.3) | 1.5% | — | Oracle Peoplesoft Enterprise Peopletools | 18/1/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Connected Query). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… |