Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.83% | — | Veraxsystems Network Management SystemAI | 25/10/2024 | 17/6/2026 | SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script. | |
| Aplazada | Alta (7.5) | 6.5% | 💥 Exploit | Severalnines Cluster ControlAI | 26/7/2024 | 9/7/2026 | Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API. | |
| Modificada | Media (5.4) | 0.24% | — | Ninjabeaveraddon Ninja Beaver Add-ons FOR Beaver Builder | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ninja Team Ninja Beaver Add-ons for Beaver Builder allows Stored XSS.This issue affects Ninja Beaver Add-ons for Beaver Builder: from n/a through 2.4.5. | |
| Analizada | Alta (8.2) | 0.53% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 16/4/2024 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 19.12.0-19.12.22, 20.12.0-20.12.21, 21.12.0-21.12.18, 22.12.0-22.12.12 and 23.12.0-23.12.2. Easily exploitable vulnerability allows… | |
| Aplazada | Alta (8.1) | 1.0% | — | Verapdf-libraryAI | 28/3/2024 | 17/6/2026 | veraPDF-library is a PDF/A validation library. Executing policy checks using custom schematron files invokes an XSL transformation that could lead to a remote code execution (RCE) vulnerability. This vulnerability is fixed in 1.24.2. | |
| Modificada | Media (5.5) | 0.19% | — | Dfeg Electronic Deliverables Creation Support Tool | 24/1/2024 | 17/6/2026 | Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be… | |
| Modificada | Alta (8.8) | 1.6% | — | Univera Panorama | 28/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Computer System Panorama allows Command Injection. This issue affects Panorama: before 8.0. | |
| Modificada | Media (6.1) | 0.55% | — | Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator | 31/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as problematic. Affected by this issue is the function get_scale of the file Master.php. The manipulation of the argument perc leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.74% | — | Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator | 31/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as critical. Affected by this vulnerability is the function get_scale of the file Master.php. The manipulation of the argument perc leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.64% | — | Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator | 31/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Grade Point Average GPA Calculator 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page with the input php://filter/read=convert.base64-encode/resource=grade_table leads to information… | |
| Modificada | Media (6.1) | 0.55% | — | Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator | 30/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Grade Point Average GPA Calculator 1.0. This affects an unknown part of the file index.php. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (5.5) | 0.21% | — | Veracode | 28/3/2023 | 17/6/2026 | A credential-leak issue was discovered in related Veracode products before 2023-03-27. Veracode Scan Jenkins Plugin before 23.3.19.0, when configured for remote agent jobs, invokes the Veracode Java API Wrapper in a manner that allows local users (with OS-level access of the Jenkins remote) to discover Veracode API… | |
| Modificada | Media (6.5) | 0.65% | — | Veracode | 28/3/2023 | 17/6/2026 | Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Jenkins global system setting debug is enabled and when a scan is configured for remote agent jobs, allows users (with access to view the job log) to discover proxy… | |
| Modificada | Media (5.5) | 0.23% | — | Jenkins Github Pull Request Coverage Status | 26/1/2023 | 17/6/2026 | Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (5.4) | 0.38% | — | Oracle Primavera Gateway | 18/1/2023 | 17/6/2026 | Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: WebUI). Supported versions that are affected are 18.8.0-18.8.15, 19.12.0-19.12.15, 20.12.0-20.12.10 and 21.12.0-21.12.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (5.3) | 0.71% | — | Jenkins Compuware Xpediter Code Coverage | 19/10/2022 | 17/6/2026 | Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process. | |
| Modificada | Media (4.3) | 0.66% | — | Jenkins Compuware Xpediter Code Coverage | 27/7/2022 | 17/6/2026 | A missing permission check in Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (5.5) | 2.6% | — | Apache TikaOracle Primavera Unifier | 16/5/2022 | 17/6/2026 | In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is… | |
| Modificada | Media (5.5) | 2.2% | — | Apache TikaOracle Primavera Unifier | 16/5/2022 | 17/6/2026 | The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. | |
| Modificada | Alta (7.8) | 0.30% | — | Sick Overall Equipment Effectiveness | 11/4/2022 | 17/6/2026 | An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated or low privilege users can modify its content. | |
| Modificada | Alta (8.1) | 1.0% | — | Jenkins Coverage/complexity Scatter Plot | 29/3/2022 | 17/6/2026 | Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Alta (7.5) | 4.9% | 💥 PoC | Fasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+32 | 11/3/2022 | 17/6/2026 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. | |
| Modificada | Media (6.5) | 12% | — | Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+25 | 24/1/2022 | 25/8/2026 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version… | |
| Modificada | Media (5.4) | 0.83% | — | Oracle Primavera Portfolio Management | 19/1/2022 | 17/6/2026 | Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web API). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2 and 20.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (5.4) | 0.83% | — | Oracle Primavera Portfolio Management | 19/1/2022 | 17/6/2026 | Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2 and 20.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… |