Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%—Ismartalarm Cubeone Firmware11/7/201717/6/2026
iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding.
ModificadaAlta (7.5)0.69%—Ismartalarm Cubeone Firmware11/7/201717/6/2026
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.
ModificadaCrítica (9.8)3.5%—Ismartalarm Cubeone Firmware11/7/201717/6/2026
On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.
ModificadaAlta (7.5)0.73%—Ismartalarm Cubeone Firmware11/7/201717/6/2026
iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.
ModificadaAlta (8.8)1.0%—Kddi Home Spot Cube 2 Firmware7/7/201717/6/2026
HOME SPOT CUBE2 firmware V101 and earlier allows an attacker to bypass authentication to load malicious firmware via WebUI.
ModificadaAlta (8.8)0.91%—Kddi Home Spot Cube 2 Firmware7/7/201717/6/2026
HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via WebUI.
ModificadaAlta (8.8)1.1%—Kddi Home Spot Cube 2 Firmware7/7/201717/6/2026
Buffer overflow in HOME SPOT CUBE2 firmware V101 and earlier allows an attacker to execute arbitrary code via WebUI.
ModificadaAlta (8)0.85%—Kddi Home Spot Cube 2 Firmware7/7/201717/6/2026
HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via Clock Settings.
ModificadaAlta (7.5)3.8%—Roundcube WebmailRoundcube Webmail23/5/201717/6/2026
Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.
ModificadaMedia (6.5)2.9%—Roundcube WebmailRoundcube Webmail23/5/201717/6/2026
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
ModificadaMedia (6.1)2.7%—Roundcube WebmailRoundcube Webmail23/5/201717/6/2026
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
ModificadaAlta (8.8)3.5%—Roundcube Webmail29/4/201717/6/2026
Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
ModificadaMedia (4.9)2.1%—Cubecart28/4/201717/6/2026
Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read arbitrary files via unspecified vectors.
ModificadaMedia (6.5)2.5%—Cubecart28/4/201717/6/2026
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (6.5)2.5%—Cubecart28/4/201717/6/2026
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (4.7)1.6%—Oracle Flexcube Universal Banking24/4/201717/6/2026
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2 and 12.0.3. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP…
ModificadaMedia (6.5)1.9%—Oracle Flexcube Universal Banking24/4/201717/6/2026
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily "exploitable" vulnerability allows low privileged attacker with network access…
ModificadaMedia (6.1)1.4%—Oracle Flexcube Enterprise Limits AND Collateral Management24/4/201717/6/2026
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.0 and 12.1.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via…
ModificadaMedia (4.7)1.6%—Oracle Flexcube Direct Banking24/4/201717/6/2026
Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Pre-Login). Supported versions that are affected are 12.0.2 and 12.0.3. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE…
ModificadaMedia (4.7)1.4%—Oracle Flexcube Universal Banking24/4/201717/6/2026
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Retail Teller). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2 and 12.0.3. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP…
ModificadaAlta (8.5)1.9%—Oracle Flexcube Enterprise Limits AND Collateral Management24/4/201717/6/2026
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.0 and 12.1.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP…
ModificadaMedia (5.4)1.1%—Oracle Flexcube Enterprise Limits AND Collateral Management24/4/201717/6/2026
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.0 and 12.1.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP…
ModificadaMedia (6.5)1.7%—Oracle Flexcube Enterprise Limits AND Collateral Management24/4/201717/6/2026
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Limits and Collateral). Supported versions that are affected are 12.0.1 and 12.1.0. Easily "exploitable" vulnerability allows low privileged attacker with network access…
ModificadaBaja (3.1)1.0%—Oracle Flexcube Enterprise Limits AND Collateral Management24/4/201717/6/2026
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Limits and Collateral). Supported versions that are affected are 12.0.0 and 12.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access…
ModificadaMedia (5.4)1.1%—Oracle Flexcube Investor Servicing24/4/201717/6/2026
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Security Management System). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Easily "exploitable" vulnerability allows low privileged attacker…
Orbitaley — Vulnerabilidades