Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
697 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.0% | — | Oracle Financial Services Analytical Applications Infrastructure | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (6.3) | 0.88% | — | Oracle Financial Services Analytical Applications Infrastructure | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.1) | 0.92% | — | Oracle Financial Services Analytical Applications Infrastructure | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (6.5) | 1.0% | — | Oracle Financial Services Analytical Applications Infrastructure | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (5.3) | 1.4% | — | Oracle Financial Services Analytical Applications Infrastructure | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (5.3) | 1.4% | — | Oracle Financial Services Analytical Applications Infrastructure | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Alta (7.1) | 1.0% | — | Oracle Financial Services Analytical Applications Infrastructure | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.1) | 0.96% | — | Oracle Financial Services Analytical Applications Infrastructure | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (5.5) | 1.0% | — | SqliteCanonical Ubuntu LinuxApple IcloudApple Ipados+12 | 27/6/2020 | 17/6/2026 | In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation. | |
| Modificada | Media (6.7) | 0.47% | — | Cisco Enterprise NFV Infrastructure Software | 18/6/2020 | 24/8/2026 | A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files. The attacker would need valid administrative credentials. This vulnerability is due to… | |
| Modificada | Alta (7.5) | 4.4% | — | SqliteFedoraproject FedoraDebian LinuxOracle Communications Messaging Server+8 | 6/6/2020 | 17/6/2026 | SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late. | |
| Modificada | Media (5.4) | 1.1% | — | Cisco Prime Infrastructure | 3/6/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by… | |
| Modificada | Media (5.5) | 0.29% | — | Cisco Application Policy Infrastructure ControllerCisco Application Services Engine | 3/6/2020 | 17/6/2026 | A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive information of other users on an affected device. The vulnerability is due to insufficient authorization limitations. An attacker could exploit this vulnerability by logging in… | |
| Modificada | Media (5.3) | 1.0% | — | Cisco Application Policy Infrastructure ControllerCisco Application Services Engine | 3/6/2020 | 17/6/2026 | A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on an affected device. The vulnerability is due to insufficient authentication of users who modify policies on an affected device. An attacker could exploit this… | |
| Modificada | Media (5.5) | 0.57% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+8 | 27/5/2020 | 17/6/2026 | ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query. | |
| Modificada | Media (5.5) | 0.62% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+14 | 27/5/2020 | 17/6/2026 | SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c. | |
| Modificada | Alta (7) | 1.0% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+15 | 27/5/2020 | 17/6/2026 | ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature. | |
| Modificada | Media (6.3) | 1.8% | — | Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+46 | 14/5/2020 | 17/6/2026 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an… | |
| Modificada | Crítica (9.8) | 7.3% | — | Dom4j Project Dom4jOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Banking Platform+34 | 1/5/2020 | 25/8/2026 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j. | |
| Modificada | Media (6.1) | 99% | 💥 Exploit | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Baja (3.7) | 8.1% | 💥 PoC | Apache Log4jOracle Communications Application Session ControllerOracle Communications Billing AND Revenue ManagementOracle Communications Eagle FTP Table Base Retrieval+42 | 27/4/2020 | 17/6/2026 | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1 | |
| Modificada | Alta (7.1) | 1.1% | — | Oracle Financial Services Analytical Applications Infrastructure | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6 - 8.0.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Crítica (9.8) | 7.6% | — | SqliteNetapp Ontap Select Deploy Administration UtilityOracle Communications Network Charging AND ControlOracle Enterprise Manager OPS Center+8 | 9/4/2020 | 17/6/2026 | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement. | |
| Modificada | Alta (7.5) | 4.3% | — | SqliteNetapp Ontap Select Deploy Administration UtilityDebian LinuxCanonical Ubuntu Linux+14 | 9/4/2020 | 17/6/2026 | SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled. | |
| Analizada | Alta (8.8) | 6.3% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+28 | 31/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). |