Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.90% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.4, 15.x, and 16.x allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote attackers to affect confidentiality and integrity via vectors related to Web access, a different vulnerability than CVE-2016-3566,… | |
| Modificada | Media (6.4) | 1.4% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote authenticated users to affect confidentiality and integrity via vectors related to Web Access. | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote attackers to affect confidentiality and integrity via vectors related to Web access, a different vulnerability than CVE-2016-3566,… | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote attackers to affect confidentiality and integrity via vectors related to Web access, a different vulnerability than CVE-2016-3566,… | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote attackers to affect confidentiality and integrity via vectors related to Web access, a different vulnerability than CVE-2016-3566,… | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote attackers to affect confidentiality and integrity via vectors related to Web access, a different vulnerability than CVE-2016-3566,… | |
| Modificada | Media (5.4) | 1.2% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote authenticated users to affect confidentiality and integrity via vectors related to Web access. | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote attackers to affect confidentiality and integrity via vectors related to Web access, a different vulnerability than CVE-2016-3568,… | |
| Modificada | Alta (8.8) | 5.1% | — | Oracle DocumakerOracle Enterprise Manager OPS CenterOracle Health Sciences Information ManagerOracle Healthcare Master Person Index+7 | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index… | |
| Modificada | Media (5.4) | 0.27% | — | Weeverapps Mcmaster Marauders | 29/9/2014 | 17/6/2026 | The McMaster Marauders (aka com.weever.marauders) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 3.4% | — | Attachmate Verastream Process Designer | 24/7/2014 | 17/6/2026 | Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to execute arbitrary code by uploading and launching an executable file. | |
| Modificada | Alta (9.3) | 2.8% | — | Attachmate Verastream Host Integrator | 6/11/2013 | 16/6/2026 | Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remote attackers to upload and execute arbitrary files via a crafted message. | |
| Modificada | Media (5) | 1.4% | — | Oracle Primavera Products Suite | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in the Instantis EnterpriseTrack component in Oracle Primavera Products Suite 8.0.6 and 8.5 allows remote attackers to affect confidentiality via unknown vectors. | |
| Modificada | Media (4) | 0.87% | — | Oracle Primavera Products Suite | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.1, 8.2, and 8.3 allows remote authenticated users to affect integrity via unknown vectors related to Web Access. | |
| Modificada | Media (4.3) | 1.0% | — | Oracle Primavera Products Suite | 17/4/2013 | 16/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 7.0, 8.1, and 8.2 allows remote attackers to affect integrity via unknown vectors related to Web Access. | |
| Modificada | Media (5.5) | 0.95% | — | Oracle Primavera Products Suite | 17/4/2013 | 16/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 7.0, 8.1, and 8.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Web Access. | |
| Modificada | Media (6.4) | 31% | 💥 Exploit | Oracle Database ServerOracle Primavera P6 Enterprise Project Portfolio Management | 21/9/2012 | 16/6/2026 | The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks,… | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | MoodleNimish Pachapurkar Spike Phpcoverage | 16/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) library, as used in Moodle 2.0.x before 2.0.2 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.9% | — | Oracle Primavera Products Suite | 3/5/2012 | 16/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 6.2.1, 8.0, 8.1, and 8.2 allows remote attackers to affect integrity via unknown vectors related to Web application. | |
| Modificada | Media (4.6) | 0.39% | — | Oracle Primavera Product Suite | 14/10/2010 | 16/6/2026 | Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 6.21.3.0 and 7.0.1.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Project Management Module. | |
| Modificada | Media (5) | 30% | — | Oracle JDKFedoraproject FedoraOpensuseSuse Linux Enterprise Server+5 | 6/8/2009 | 16/6/2026 | XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the… | |
| Modificada | Media (6.4) | 1.0% | — | Albinoloverats Anubis Plugin | 19/6/2008 | 16/6/2026 | The Anubis (aka Anubis+Ripe160) plugin before 1.3 for encrypt stores the unencrypted file's size in cleartext in the header of the encrypted file, which allows attackers to distinguish between encrypted data and random padding at the end of the encrypted file. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Daverave Link Bank | 14/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in iframe.php in daverave Link Bank allows remote attackers to inject arbitrary web script or HTML via the site parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Daverave Link Bank | 14/3/2006 | 16/6/2026 | Direct static code injection vulnerability in add_link.txt in daverave Link Bank allows remote attackers to execute arbitrary PHP code via the url_name parameter, which is not sanitized before being stored in links.txt, which is later used in an include statement. |