Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.1% | — | Vikwp Vikbooking Hotel Booking Engine & Property Management System Plugin | 19/4/2022 | 17/6/2026 | Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests. | |
| Modificada | Crítica (9.8) | 1.7% | — | Vikwp Vikbooking Hotel Booking Engine & Property Management System Plugin | 19/4/2022 | 17/6/2026 | Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form. | |
| Modificada | Alta (7.5) | 12% | — | Apache TomcatNetapp HCINetapp Management Services FOR Element SoftwareDebian Linux+14 | 14/10/2021 | 17/6/2026 | The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a… | |
| Modificada | Media (5.3) | 75% | — | Apache TomcatApache TomeeDebian LinuxOracle Agile Product Lifecycle Management+18 | 12/7/2021 | 25/8/2026 | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if… | |
| Modificada | Media (6.5) | 9.9% | — | Apache TomcatOracle Communications Cloud Native Core PolicyOracle Communications Diameter Signaling RouterOracle Communications Pricing Design Center+3 | 12/7/2021 | 17/6/2026 | A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65. | |
| Modificada | Alta (8.8) | 3.3% | — | Pivotal Software Spring SecurityVmware Spring SecurityOracle Communications Element ManagerOracle Communications Interactive Session Recorder+4 | 23/2/2021 | 17/6/2026 | Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the… | |
| Modificada | Alta (8.8) | 1.2% | — | Changjia Property Management System Project Changjia Property Management System | 17/2/2021 | 17/6/2026 | Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions. | |
| Modificada | Alta (7.5) | 1.8% | — | Changjia Property Management System Project Changjia Property Management System | 17/2/2021 | 17/6/2026 | The CGE page with download function contains a Directory Traversal vulnerability. Attackers can use this loophole to download system files arbitrarily. | |
| Modificada | Alta (7.5) | 1.5% | — | Changjia Property Management System Project Changjia Property Management System | 17/2/2021 | 17/6/2026 | The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (7.6) | 0.91% | — | Oracle Hospitality Cruise Shipboard Property Management System | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS Suite). The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle… | |
| Modificada | Media (5.1) | 0.42% | — | Oracle Hospitality Cruise Shipboard Property Management System | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: DGS RES Online, FMS Sender, FMS Receiver, OHC WPF Security). The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker… | |
| Modificada | Media (6.7) | 0.37% | — | Oracle Hospitality Cruise Shipboard Property Management System | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS Suite). The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle… | |
| Modificada | Media (5.5) | 0.44% | — | Oracle Hospitality Cruise Shipboard Property Management System | 17/10/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: OHC ENOAD). The supported version that is affected is 8.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle… | |
| Modificada | Alta (7.7) | 0.50% | — | Oracle Hospitality Cruise Shipboard Property Management System | 17/10/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: OHC Admin, OHC Management). The supported version that is affected is 8.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure… | |
| Modificada | Media (6.2) | 0.52% | — | Oracle Hospitality Cruise Shipboard Property Management System | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS Suite). The supported version that is affected is 8.x. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle… | |
| Modificada | Alta (7.1) | 0.58% | — | Oracle Hospitality Cruise Shipboard Property Management System | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS Suite). The supported version that is affected is 8.x. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle… | |
| Modificada | Alta (8.2) | 1.4% | — | Oracle Hospitality Cruise Shipboard Property Management System | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: Mobile Gangway and Mustering). The supported version that is affected is 7.3.874. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP… | |
| Modificada | Media (6.4) | 1.2% | — | Oracle Hospitality Cruise Shipboard Property Management System | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: OHC DRS). The supported version that is affected is 8.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (5.4) | 1.2% | — | Oracle Hospitality Cruise Shipboard Property Management System | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: Module). The supported version that is affected is 8.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… |