Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
659 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 1.5% | — | Oracle E-business Suite | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Messages). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (4.7) | 1.2% | — | Oracle E-business Suite | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Messages). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (4.7) | 1.2% | — | Oracle E-business Suite | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Message Display). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Media (4.7) | 1.2% | — | Oracle E-business Suite | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Message Display). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Crítica (9.1) | 2.1% | — | Oracle E-business Suite | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: OCM Query). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (5.3) | 1.5% | — | Oracle E-business Suite | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Session Management). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP… | |
| Modificada | Media (4.7) | 1.2% | — | Oracle E-business Suite | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Mobile Field Service component of Oracle E-Business Suite (subcomponent: Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access… | |
| Modificada | Alta (8.2) | 1.5% | — | Oracle E-business Suite | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: Partner Detail). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access… | |
| Modificada | Crítica (9.1) | 2.0% | — | Oracle E-business Suite | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Performance Management component of Oracle E-Business Suite (subcomponent: Performance Management Plan). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (8.2) | 1.5% | — | Oracle E-business Suite | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Alta (8.2) | 1.5% | — | Oracle E-business Suite | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User Registration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (4.7) | 1.2% | — | Oracle E-business Suite | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Messages). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Webex Business Suite | 10/1/2019 | 17/6/2026 | A vulnerability in the MyWebex component of Cisco Webex Business Suite could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by convincing a user to click a… | |
| Modificada | Media (5.9) | 12% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js+15 | 30/10/2018 | 17/6/2026 | The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected… | |
| Modificada | Media (6.1) | 1.4% | — | Cisco Webex Business Suite 31Cisco Webex Business Suite 32Cisco Webex Business Suite 33Cisco Webex Meetings Online | 5/10/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Webex Events Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface… | |
| Modificada | Alta (7.3) | 0.49% | — | Cisco Webex Meetings ServerCisco Webex Meetings OnlineCisco Webex Business Suite 32 | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and… | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Business Suite 32Cisco Webex Business Suite 33 | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and… | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Business Suite 32Cisco Webex Business Suite 33 | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and… | |
| Modificada | Alta (7.8) | 2.1% | — | Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Business Suite 32Cisco Webex Business Suite 33 | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and… | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Business Suite 32Cisco Webex Business Suite 33 | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and… | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Business Suite 32Cisco Webex Business Suite 33+1 | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and… | |
| Modificada | Alta (7.8) | 2.1% | — | Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Business Suite 32Cisco Webex Business Suite 33 | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and… | |
| Modificada | Alta (7.8) | 2.1% | — | Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Business Suite 32Cisco Webex Business Suite 33 | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and… | |
| Modificada | Alta (7.8) | 2.1% | — | Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Business Suite 32Cisco Webex Business Suite 33 | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and… | |
| Modificada | Alta (7.8) | 2.1% | — | Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Business Suite 32Cisco Webex Business Suite 33 | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and… |