Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 1.9% | — | Oracle Field Service | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Field Service component of Oracle E-Business Suite (subcomponent: Wireless/WAP). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Field Service. Successful… | |
| Modificada | Media (6.1) | 1.1% | — | Webhammer WP Custom Fields Search | 15/6/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows remote attackers to inject arbitrary JavaScript via the cs-all-0 parameter. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa💥 Exploit | HPE Proliant Ml10 Gen9 Server FirmwareSiemens Simatic Itp1000 FirmwareSiemens Simatic Ipc847d FirmwareSiemens Simatic Ipc847c Firmware+32 | 2/5/2017 | 17/6/2026 | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel… | |
| Modificada | Crítica (9.1) | 2.0% | — | Oracle Field Service | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Field Service component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Wireless. | |
| Modificada | Media (4.3) | 1.5% | — | Oracle Field Service | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Field Service component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via unknown vectors related to Field Service Map. | |
| Modificada | Media (6.1) | 0.62% | — | Field Group Project Field Group | 8/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Field Group module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with permission to configure field display settings to inject arbitrary web script or HTML via an element attribute. | |
| Modificada | Media (5) | 1.2% | — | Field AS Block Project Field AS Block | 6/11/2015 | 17/6/2026 | The Field as Block module 7.x-1.x before 7.x-1.4 for Drupal might allow remote attackers to obtain sensitive field information by reading a cached block. | |
| Modificada | Baja (3.5) | 0.79% | — | Fieldable Panels Panes Project Fieldable Panels Panes | 17/9/2015 | 17/6/2026 | The Fieldable Panels Panes module 7.x-1.x before 7.x-1.7 for Drupal does not properly check permissions to edit Fieldable Panels Panes entities, which allows remote authenticated users to edit panes by leveraging permissions to edit panels. | |
| Modificada | Baja (3.5) | 0.95% | — | Node Field Project Node Field | 6/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Node Field module 7.x-2.x before 7.x-2.45 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors involving internal fields. | |
| Modificada | Baja (2.1) | 0.94% | — | Imagefield Info Project Imagefield Info | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Imagefield Info module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "Administer image styles" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 0.93% | — | IBM Sterling Field SalesIBM Sterling Order ManagementIBM Sterling Selling AND Fulfillment Foundation | 25/5/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Sterling Order Management 8.5 before HF113, Sterling Selling and Fulfillment Foundation 9.0.0 before FP92, and Sterling Field Sales (SFS) 9.0 before HF7 in IBM Sterling Selling and Fulfillment Suite allows remote attackers to inject arbitrary web script or HTML via a crafted… | |
| Modificada | Media (5) | 1.8% | — | Django-markupfield Project Django-markupfield | 24/4/2015 | 17/6/2026 | django-markupfield before 1.3.2 uses the default docutils RESTRUCTUREDTEXT_FILTER_SETTINGS settings, which allows remote attackers to include and read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.8) | 0.64% | — | Joshics Contact Form Fields | 21/4/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Contact Form Fields module before 6.x-2.3 for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete fields via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.95% | — | Field Display Label Project Field Display Label | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Field Display Label module before 7.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the alternate field label in content types settings. | |
| Modificada | Media (4) | 1.6% | — | Filefield Project Filefield | 1/12/2014 | 17/6/2026 | The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded file. | |
| Modificada | Baja (3.5) | 0.95% | — | Tablefield Project Tablefield | 21/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the TableField module 7.x-2.x before 7.x-2.3 allows remote authenticated users with the "administer content types" or "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related to the field help text in an entity edit form. | |
| Modificada | Media (5.4) | 0.30% | — | Webprancer Garfield's Diner | 9/9/2014 | 17/6/2026 | The Garfield's Diner (aka com.webprancer.google.GarfieldsDiner) application 1.4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.30% | — | Webprancer Garfield's Defense | 9/9/2014 | 17/6/2026 | The Garfield's Defense (aka com.webprancer.google.garfieldDefense) application 1.5.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (3.5) | 0.95% | — | Newsignature Addressfield Tokens | 2/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the address components field formatter in the AddressField Tokens module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via an address field. | |
| Modificada | Media (4) | 1.1% | — | Nathan Haug Filefield Sources | 13/5/2014 | 16/6/2026 | The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file permissions, which allows remote authenticated users to read arbitrary files by attaching a file. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | Cru-inc Ditto Forensic Fieldstation FirmwareCru-inc Ditto Forensic Fieldstation | 7/1/2014 | 17/6/2026 | The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | Cru-inc Ditto Forensic Fieldstation FirmwareCru-inc Ditto Forensic Fieldstation | 7/1/2014 | 17/6/2026 | CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the forensic imaging task. | |
| Modificada | Media (6.8) | 2.5% | 💥 Exploit | Cru-inc Ditto Forensic Fieldstation FirmwareCru-inc Ditto Forensic Fieldstation | 17/12/2013 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to hijack the authentication of administrators for requests that modify the disk erase technique settings via unspecified vectors. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Cru-inc Ditto Forensic Fieldstation FirmwareCru-inc Ditto Forensic Fieldstation | 17/12/2013 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web script or HTML via the username parameter in a login or (2) remote authenticated users to inject arbitrary web script or HTML via unspecified… |