Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
443 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.5% | — | Oracle Applications Framework | 17/10/2018 | 17/6/2026 | Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: REST Services). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Alta (8.1) | 18% | — | Zohocorp Manageengine Applications Manager | 26/9/2018 | 17/6/2026 | A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share. | |
| Modificada | Media (6.1) | 1.7% | — | Zohocorp Manageengine Applications Manager | 8/8/2018 | 17/6/2026 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter. | |
| Modificada | Crítica (9.8) | 3.9% | — | Zohocorp Manageengine Applications Manager | 8/8/2018 | 17/6/2026 | A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request. | |
| Modificada | Media (6.1) | 11% | 💥 PoC | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+34 | 2/8/2018 | 17/6/2026 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. | |
| Modificada | Alta (7.5) | 2.7% | — | Oracle Applications Manager | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP… | |
| Modificada | Crítica (9.8) | 21% | — | Zohocorp Manageengine Applications Manager | 13/7/2018 | 17/6/2026 | ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating system. As Application Manager's RMI… | |
| Modificada | Media (4.9) | 2.5% | — | Zohocorp Manageengine Applications Manager | 13/7/2018 | 17/6/2026 | ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored private keys, etc. By default Application… | |
| Modificada | Alta (8.8) | 1.7% | — | Zohocorp Manageengine Applications Manager | 13/7/2018 | 17/6/2026 | In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another user, e.g. change another user's password. | |
| Modificada | Crítica (9.8) | 40% | — | Zohocorp Manageengine Applications Manager | 2/7/2018 | 17/6/2026 | A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request. | |
| Modificada | Media (6.1) | 3.5% | — | Zohocorp Manageengine Applications Manager | 29/6/2018 | 17/6/2026 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do. | |
| Modificada | Crítica (9.1) | 6.3% | — | Zohocorp Manageengine Applications Manager | 6/6/2018 | 17/6/2026 | Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by sending a specially crafted request to the… | |
| Modificada | Media (6.1) | 1.7% | — | Manageengine Applications Manager | 5/6/2018 | 17/6/2026 | ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Scripting vulnerability in parameter LIMIT, in URL path /DiagAlertAction.do?REQTYPE=AJAX&LIMIT=1233. The URL is also available without… | |
| Modificada | Crítica (9.8) | 4.7% | 💥 Exploit | Manageengine Applications Manager | 5/6/2018 | 17/6/2026 | ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes… | |
| Modificada | Crítica (9.8) | 19% | — | Apache BatikDebian LinuxCanonical Ubuntu LinuxOracle Business Intelligence+17 | 24/5/2018 | 17/6/2026 | In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization. | |
| Modificada | Media (6.5) | 8.6% | — | Microsoft OfficeMicrosoft Office Compatibility PackMicrosoft Sharepoint ServerMicrosoft WEB Applications | 9/5/2018 | 17/6/2026 | An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Word, Microsoft Office. | |
| Modificada | Crítica (9.8) | 79% | 💥 Exploit | Zohocorp Manageengine Applications Manager | 8/3/2018 | 17/6/2026 | A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls several internal classes, and then… | |
| Modificada | Crítica (9.8) | 38% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+17 | 6/2/2018 | 17/6/2026 | A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. | |
| Modificada | Crítica (9.8) | 8.4% | — | Fasterxml Jackson-databindDebian LinuxRedhat Openshift Container PlatformRedhat Satellite+20 | 6/2/2018 | 17/6/2026 | A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting… | |
| Modificada | Media (6.1) | 30% | 💥 PoC | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Media (6.1) | 1.1% | — | Oracle Financial Services Analytical Applications Reconciliation Framework | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Reconciliation Framework component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Media (6.1) | 1.3% | — | Oracle Financial Services Analytical Applications Infrastructure | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 7.3.5.x and 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Alta (7.4) | 1.1% | — | Oracle Financial Services Analytical Applications Infrastructure | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 7.3.5.x and 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (4.4) | 0.43% | — | Oracle Applications DBA | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Applications DBA component of Oracle E-Business Suite (subcomponent: ADPatch). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle… | |
| Modificada | Alta (7.8) | 0.50% | — | Vmware Vrealize Operations FOR HorizonVmware Vrealize Operations FOR Published Applications | 5/1/2018 | 17/6/2026 | The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM. |