Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Oracle Hyperion BI+ | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). Supported versions that are affected are 11.1.2.4 and 11.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion BI+. Successful attacks… | |
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modificada | Alta (7.5) | 1.7% | — | Oracle Hyperion Essbase Administration Services | 21/7/2021 | 17/6/2026 | Vulnerability in the Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Console). Supported versions that are affected are 11.1.2.4 and 21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Essbase Administration… | |
| Modificada | Alta (8.6) | 1.7% | — | Oracle Hyperion Essbase Administration Services | 21/7/2021 | 17/6/2026 | Vulnerability in the Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Console). Supported versions that are affected are 11.1.2.4 and 21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Essbase Administration… | |
| Modificada | Media (5.2) | 0.89% | — | Oracle Hyperion Infrastructure Technology | 21/7/2021 | 17/6/2026 | Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology.… | |
| Modificada | Media (6.5) | 10% | 💥 Exploit | Eclipse MojarraOracle Banking Enterprise Default ManagementOracle Banking PlatformOracle Communications Network Integrity+5 | 2/6/2021 | 17/6/2026 | Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter. | |
| Modificada | Crítica (10) | 1.8% | — | Oracle Essbase Analytic Provider ServicesOracle Hyperion Analytic Provider Services | 22/4/2021 | 17/6/2026 | Vulnerability in the Hyperion Analytic Provider Services product of Oracle Hyperion (component: JAPI) and Essbase Analytic Provider Services product of Oracle Essbase (component: JAPI). Supported versions that are affected are Hyperion Analytic Provider Services 11.1.2.4 and 12.2.1.4, and Essbase Analytic Provider… | |
| Modificada | Baja (3.9) | 0.58% | — | Oracle Hyperion Financial Management | 22/4/2021 | 17/6/2026 | Vulnerability in the Hyperion Financial Management product of Oracle Hyperion (component: Task Automation). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Management. Successful attacks… | |
| Modificada | Media (5.5) | 3.3% | — | Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+15 | 19/3/2021 | 17/6/2026 | A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. | |
| Modificada | Media (5.5) | 3.0% | — | Apache PdfboxFedoraproject FedoraOracle Banking Trade Finance Process ManagementOracle Banking Treasury Management+11 | 19/3/2021 | 17/6/2026 | A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. | |
| Modificada | Media (5) | 0.32% | — | Oracle Enterprise Manager OPS CenterOracle Hyperion Infrastructure TechnologyOracle ZFS Storage Appliance | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: RAS subsystems). The supported version that is affected is 8.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise… | |
| Modificada | Baja (2.4) | 1.3% | — | Oracle Agile Engineering Data ManagementOracle Hyperion Infrastructure TechnologyOracle Siebel UI FrameworkOracle Weblogic Server | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Media (4.8) | 0.81% | — | Oracle Database ServerOracle Enterprise Manager OPS CenterOracle Hyperion Infrastructure TechnologyOracle ZFS Storage Appliance | 20/1/2021 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. Successful attacks… | |
| Modificada | Media (4.8) | 8.3% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkOracle Blockchain Platform+13 | 28/11/2020 | 17/6/2026 | In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely… | |
| Modificada | Alta (7.5) | 11% | — | Apache BatikOracle API GatewayOracle Business IntelligenceOracle Communications Application Session Controller+14 | 12/11/2020 | 17/6/2026 | Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. | |
| Modificada | Alta (7.5) | 5.3% | — | CodemirrorOracle Application ExpressOracle Enterprise Manager Express User InterfaceOracle Essbase+2 | 30/10/2020 | 17/6/2026 | This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the… | |
| Modificada | Media (6.1) | 1.3% | — | Oracle Hyperion Infrastructure Technology | 21/10/2020 | 17/6/2026 | Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology.… | |
| Modificada | Media (4.2) | 0.84% | — | Oracle Hyperion Lifecycle Management | 21/10/2020 | 17/6/2026 | Vulnerability in the Hyperion Lifecycle Management product of Oracle Hyperion (component: Shared Services). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Lifecycle Management. Successful attacks… | |
| Modificada | Baja (2) | 0.82% | — | Oracle Hyperion BI+ | 21/10/2020 | 17/6/2026 | Vulnerability in the Hyperion BI+ product of Oracle Hyperion (component: IQR-Foundation service). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise Hyperion BI+. Successful attacks require… | |
| Modificada | Media (4.3) | 0.49% | — | Oracle Hyperion Analytic Provider Services | 21/10/2020 | 17/6/2026 | Vulnerability in the Hyperion Analytic Provider Services product of Oracle Hyperion (component: Smart View Provider). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where… | |
| Modificada | Media (4.2) | 1.0% | — | Oracle Hyperion BI+ | 21/10/2020 | 17/6/2026 | Vulnerability in the Hyperion BI+ product of Oracle Hyperion (component: IQR-Foundation service). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise Hyperion BI+. Successful attacks require… | |
| Modificada | Media (4.2) | 0.80% | — | Oracle Hyperion Planning | 21/10/2020 | 17/6/2026 | Vulnerability in the Hyperion Planning product of Oracle Hyperion (component: Application Development Framework). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Planning. Successful attacks… | |
| Modificada | Media (4.2) | 0.78% | — | Oracle Hyperion Lifecycle Management | 21/10/2020 | 17/6/2026 | Vulnerability in the Hyperion Lifecycle Management product of Oracle Hyperion (component: Shared Services). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Lifecycle Management. Successful attacks… | |
| Modificada | Media (6.5) | 11% | 💥 PoC | Vmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRMOracle Communications Design Studio+34 | 19/9/2020 | 17/6/2026 | In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter. | |
| Modificada | Alta (7.5) | 89% | — | Apache Http ServerOracle Communications Element ManagerOracle Communications Session Report ManagerOracle Communications Session Route Manager+21 | 7/8/2020 | 17/6/2026 | Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers. |