Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
443 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.7% | — | Oracle Communications Applications | 21/10/2015 | 17/6/2026 | Unspecified vulnerability in the Oracle Communications Convergence component in Oracle Communications Applications 2.0 and 3.0.1 allows remote attackers to affect confidentiality via unknown vectors related to Mail Proxy. | |
| Modificada | Alta (10) | 3.1% | — | Oracle Communications Applications | 21/10/2015 | 17/6/2026 | Unspecified vulnerability in (1) the Oracle Communications Diameter Signaling Router (DSR) component in Oracle Communications Applications 4.1.6 and earlier, 5.1.0 and earlier, 6.0.2 and earlier, and 7.1.0 and earlier; (2) the Oracle Communications Performance Intelligence Center Software component in Oracle… | |
| Modificada | Baja (2.1) | 0.41% | — | Oracle Health Sciences Applications | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in the Oracle Health Sciences Argus Safety component in Oracle Health Sciences Applications 8.0 allows local users to affect confidentiality via vectors related to BIP Installer. | |
| Modificada | Media (4.3) | 1.5% | — | Oracle Retail Applications | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in the Oracle Retail Central Office component in Oracle Retail Applications 13.1, 13.2, 13.3, 13.4, 14.0, and 14.1 allows remote attackers to affect integrity via unknown vectors. | |
| Modificada | Media (4.3) | 1.9% | — | Oracle Retail Applications | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in the Oracle Retail Back Office component in Oracle Retail Applications 12.0, 12.0IN, 13.0, 13.1, 13.2, 13.3, 13.4, 14.0, and 14.1 allows remote attackers to affect integrity via unknown vectors. | |
| Modificada | Alta (9.3) | 13% | — | Microsoft OfficeMicrosoft Office Compatibility PackMicrosoft Office WEB Apps ServerMicrosoft Sharepoint Server+3 | 11/3/2015 | 17/6/2026 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 Gold and SP1, Word 2013 RT Gold and SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 Gold and SP1, Web Applications 2010 SP2, and Web Apps Server… | |
| Modificada | Alta (9.3) | 19% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office Compatibility Pack+7 | 11/3/2015 | 17/6/2026 | Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 Gold and SP1, Word 2013 Gold and SP1, Office 2013 RT Gold and SP1, Word 2013 RT Gold and SP1, Excel Viewer, Office… | |
| Modificada | Alta (9.3) | 30% | 💥 Exploit | Microsoft WEB ApplicationsMicrosoft Office Compatibility PackMicrosoft Word Automation ServicesMicrosoft Word+3 | 11/2/2015 | 17/6/2026 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applications 2010 SP2, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka… | |
| Modificada | Media (6.8) | 1.4% | — | Oracle Retail Applications Xstore | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in the MICROS Retail component in Oracle Retail Applications Xstore: 3.2.1, 3.4.2, 3.5.0, 4.0.1, 4.5.1, 4.8.0, 5.0.3, 5.5.3, 6.0.6, and 6.5.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Xstore Point of Sale. | |
| Modificada | Alta (7.6) | 4.5% | 💥 PoC | Oracle Communications Applications | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in the Oracle Communications Diameter Signaling Router component in Oracle Communications Applications 3.x, 4.x, and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Signaling - DPI. | |
| Modificada | Media (5) | 2.1% | — | KDE Applications | 18/1/2015 | 17/6/2026 | kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack. | |
| Modificada | Alta (9.3) | 14% | — | Microsoft OfficeMicrosoft Office Compatibility PackMicrosoft Sharepoint ServerMicrosoft WEB Applications+1 | 11/12/2014 | 17/6/2026 | Use-after-free vulnerability in Microsoft Office 2010 SP2, Office 2013 Gold and SP1, Office 2013 RT Gold and SP1, Office for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 Gold and SP1, and Office Web Apps 2010 SP2 and 2013 Gold and SP1 allows… | |
| Modificada | Media (6.3) | 1.00% | — | Oracle Communications Applications | 15/10/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Communications Session Border Controller component in Oracle Communications Applications SCX640m5 allows remote authenticated users to affect availability via unknown vectors related to Lawful Intercept. | |
| Modificada | Alta (8.5) | 10% | — | Microsoft WEB Applications | 14/5/2014 | 17/6/2026 | Microsoft Web Applications 2010 SP1 and SP2 allows remote authenticated users to execute arbitrary code via crafted page content, aka "Web Applications Page Content Vulnerability." | |
| Modificada | Alta (9) | 14% | — | Microsoft Office WEB Apps ServerMicrosoft Project ServerMicrosoft Sharepoint DesignerMicrosoft Sharepoint Foundation+4 | 14/5/2014 | 17/6/2026 | Microsoft Windows SharePoint Services 3.0 SP3; SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1; SharePoint Foundation 2010 SP1 and SP2 and 2013 Gold and SP1; Project Server 2010 SP1 and SP2 and 2013 Gold and SP1; Web Applications 2010 SP1 and SP2; Office Web Apps Server 2013 Gold and SP1;… | |
| Modificada | Alta (7.5) | 83% | 💥 Exploit | Oracle Retail ApplicationsApache Commons FileuploadApache Tomcat | 1/4/2014 | 7/10/2026 | MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions. | |
| Modificada | Alta (7.2) | 0.30% | — | Novell Suse Linux Enterprise FOR SAP Applications | 2/12/2013 | 16/6/2026 | Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 allows local users to have an unspecified impact via vectors related to a tmp/ directory. | |
| Modificada | Baja (3.6) | 0.97% | — | Oracle Industry Applications | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, and 5.0 SP1a-b allows remote authenticated users to affect confidentiality and integrity via unknown… | |
| Modificada | Baja (3.6) | 0.97% | — | Oracle Industry Applications | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, 5.0 SP1a-b, 5.5 SP0, 5.5 SP0b, 5.5.1, and 6.0.0 allows remote authenticated users to affect… | |
| Modificada | Baja (2.1) | 0.81% | — | Oracle Industry Applications | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, 5.0 SP1a-b, 5.0.3, and 5.0.4 allows remote authenticated users to affect confidentiality via unknown vectors related to… | |
| Modificada | Baja (3.5) | 0.88% | — | Oracle Industry Applications | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, and 5.0 SP1a-b allows remote authenticated users to affect confidentiality via unknown vectors related… | |
| Modificada | Baja (2.4) | 0.25% | — | Oracle Industry Applications | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle Siebel CTMS component in Oracle Industry Applications 8.1.1.x allows local users to affect confidentiality and availability via unknown vectors related to SC-OC Integration. | |
| Modificada | Media (5.5) | 0.96% | — | Oracle Industry Applications | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle Retail Invoice Matching component in Oracle Industry Applications 10.2, 11.0, 12.0, 12.0IN, 12.1, 13.0, 13.1, and 13.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to System Administration. | |
| Modificada | Media (4) | 1.1% | — | Oracle Industry Applications | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle Policy Automation component in Oracle Industry Applications 10.2.0, 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Determinations Engine. | |
| Modificada | Media (5.5) | 0.95% | — | Oracle Industry Applications | 17/4/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle Retail Central Office component in Oracle Industry Applications 13.1, 13.2, 13.3, and 13.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Customer Operations (Add, Search). |