Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
737 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.3% | — | CodemirrorOracle Application ExpressOracle Enterprise Manager Express User InterfaceOracle Essbase+2 | 30/10/2020 | 17/6/2026 | This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the… | |
| Modificada | Media (5.4) | 0.70% | — | Oracle Application Express | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application… | |
| Modificada | Media (5.4) | 0.70% | — | Oracle Application Express | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application… | |
| Modificada | Media (5.4) | 0.73% | — | Oracle Application Express | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application… | |
| Modificada | Media (5.4) | 0.73% | — | Oracle Application Express | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express Quick Poll component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application… | |
| Modificada | Media (5.4) | 0.73% | — | Oracle Application Express | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful… | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco ExpresswayCisco Telepresence Video Communication Server | 8/10/2020 | 17/6/2026 | A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect handling of incoming SIP… | |
| Modificada | Media (6.1) | 4.9% | — | Cure53 DompurifyDebian LinuxMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+1 | 7/10/2020 | 17/6/2026 | Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements. | |
| Modificada | Alta (7.2) | 3.4% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 23/9/2020 | 17/6/2026 | A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to upload arbitrary files and execute commands on the underlying operating system. To exploit this vulnerability, an attacker needs valid Administrator credentials.… | |
| Modificada | Alta (7.5) | 69% | — | NEC Expresscluster X | 10/9/2020 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the clpwebmc executable. Due to the improper restriction of XML External Entity (XXE)… | |
| Modificada | Crítica (9.8) | 3.4% | — | Property-expr Project Property-expr | 18/8/2020 | 17/6/2026 | The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function. | |
| Modificada | Media (6.5) | 1.0% | — | Expresstech Quiz AND Survey Master | 16/8/2020 | 17/6/2026 | php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element. | |
| Modificada | Crítica (9.8) | 4.8% | 💥 PoC | Express-fileupload Project Express-fileuploadNetapp MAX Data | 30/7/2020 | 17/6/2026 | This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution. | |
| Modificada | Media (4.6) | 0.70% | — | Oracle Application Express | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express. Successful… | |
| Modificada | Media (5.4) | 0.69% | — | Oracle Application Express | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks… | |
| Modificada | Media (5.4) | 0.69% | — | Oracle Application Express | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks… | |
| Modificada | Media (5.4) | 0.69% | — | Oracle Application Express | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks… | |
| Modificada | Media (5.4) | 0.69% | — | Oracle Application Express | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks… | |
| Modificada | Media (5.4) | 0.66% | — | Oracle Application Express | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks… | |
| Modificada | Media (5.4) | 0.70% | — | Oracle Application Express | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks… | |
| Modificada | Media (5.4) | 0.66% | — | Oracle Application Express | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks… | |
| Modificada | Alta (7.8) | 2.1% | — | Phoenixcontact PC WorxPhoenixcontact PC Worx Express | 1/7/2020 | 17/6/2026 | mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation. | |
| Modificada | Alta (7.8) | 15% | — | Phoenixcontact PC WorxPhoenixcontact PC Worx Express | 1/7/2020 | 17/6/2026 | PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation. | |
| Modificada | Crítica (9.1) | 1.1% | — | Auth0 Express-jwt | 30/6/2020 | 17/6/2026 | In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass. You are affected by this vulnerability if all of… | |
| Modificada | Alta (8.8) | 0.58% | — | Cabsoftware Reportexpress Proplus | 29/6/2020 | 17/6/2026 | Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp). |