Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1090 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.92% | — | Google GuavaQuarkusOracle Commerce Guided SearchOracle Communications Cloud Native Core Network Slice Selection Function+9 | 10/12/2020 | 17/6/2026 | A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable… | |
| Modificada | Media (5.9) | 7.1% | 💥 PoC | OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+40 | 8/12/2020 | 17/6/2026 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both… | |
| Modificada | Media (5.3) | 9.0% | — | Apache HttpclientQuarkusOracle Data IntegratorOracle JD Edwards Enterpriseone Orchestrator+13 | 2/12/2020 | 17/6/2026 | Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. | |
| Modificada | Media (6.1) | 2.0% | — | CkeditorOracle Agile Product Lifecycle ManagementOracle Application ExpressOracle Banking Party Management+5 | 12/11/2020 | 25/8/2026 | A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs. | |
| Modificada | Alta (8.1) | 1.6% | — | Oracle Peoplesoft Enterprise SCM Esupplier Connection | 21/10/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise SCM eSupplier Connection product of Oracle PeopleSoft (component: eSupplier Connection). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM… | |
| Modificada | Baja (2.7) | 0.97% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Modificada | Media (6.1) | 1.0% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (6.1) | 1.0% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Grids). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Media (5.3) | 1.4% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Modificada | Media (6.1) | 0.92% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (6.1) | 0.96% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (6.5) | 1.6% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Media (6.3) | 0.88% | — | Oracle Peoplesoft Enterprise Human Capital Management Global Payroll Core | 21/10/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Core.… | |
| Modificada | Baja (3.7) | 4.9% | — | OpensslCanonical Ubuntu LinuxDebian LinuxOracle JD Edwards World Security+11 | 9/9/2020 | 17/6/2026 | The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent… | |
| Modificada | Media (6.5) | 3.0% | — | Xmlsoft Libxml2Debian LinuxFedoraproject FedoraOpensuse Leap+14 | 4/9/2020 | 17/6/2026 | GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e. | |
| Modificada | Media (6.7) | 1.2% | — | Elasticsearch KibanaOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Peoplesoft Enterprise Peopletools | 27/7/2020 | 17/6/2026 | In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization. | |
| Modificada | Media (4.8) | 1.1% | — | Elasticsearch KibanaOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Peoplesoft Enterprise Peopletools | 27/7/2020 | 17/6/2026 | Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive. | |
| Modificada | Media (6.1) | 0.98% | — | Oracle Peoplesoft Enterprise Peopletools | 15/7/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Modificada | Media (5.4) | 0.77% | — | Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway | 15/7/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HRMS product of Oracle PeopleSoft (component: Time and Labor). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HRMS. Successful attacks of this… | |
| Modificada | Media (4.3) | 1.1% | — | Oracle Peoplesoft Enterprise Peopletools | 15/7/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Media (6.1) | 0.96% | — | Oracle Peoplesoft Enterprise Peopletools | 15/7/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Media (5.4) | 0.77% | — | Oracle Peoplesoft Products | 15/7/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks of… | |
| Modificada | Baja (2.7) | 0.86% | — | Oracle Peoplesoft Enterprise Peopletools | 15/7/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Environment Mgmt Console). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (5.3) | 1.4% | — | Oracle Peoplesoft Enterprise Peopletools | 15/7/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Modificada | Alta (7.4) | 5.2% | — | LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+14 | 15/7/2020 | 17/6/2026 | Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. |