Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.0% | — | Vmware Spring FrameworkRedhat OpenshiftOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+26 | 11/5/2018 | 17/6/2026 | Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that… | |
| Modificada | Crítica (9.8) | 2.4% | — | IBM Security Guardium Database Activity Monitor | 2/5/2018 | 17/6/2026 | IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132624. | |
| Modificada | Media (5.9) | 5.1% | — | Google GuavaRedhat Openshift Container PlatformRedhat OpenstackRedhat Satellite+13 | 26/4/2018 | 17/6/2026 | Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the… | |
| Modificada | Alta (8.5) | 1.7% | — | Oracle Database Server | 19/4/2018 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java… | |
| Modificada | Alta (8.8) | 34% | 💥 Exploit | Cognitect DatomicH2database H2 | 11/4/2018 | 17/6/2026 | H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment." | |
| Modificada | Crítica (9.6) | 7.3% | 💥 Exploit | Contact-form-7-to-database-extension Project Contact-form-7-to-database-extension | 4/4/2018 | 17/6/2026 | CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form. | |
| Modificada | Media (4.3) | 0.97% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy OptimizationIBM Maximo FOR Aviation+10 | 27/3/2018 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via… | |
| Modificada | Media (5.5) | 0.34% | — | IBM Security Guardium Database Activity Monitor | 12/3/2018 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 10 allows local users to obtain sensitive information by reading cached browser data. IBM X-Force ID: 110328. | |
| Modificada | Alta (8.2) | 0.34% | — | IBM Security Guardium Database Activity Monitor | 12/3/2018 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB systems. IBM X-Force ID: 110326. | |
| Modificada | Media (4.4) | 0.29% | — | IBM Security Guardium Database Activity Monitor | 9/2/2018 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not suppose to. IBM X-Force ID: 137765. | |
| Modificada | Crítica (9.8) | 8.4% | — | Fasterxml Jackson-databindDebian LinuxRedhat Openshift Container PlatformRedhat Satellite+20 | 6/2/2018 | 17/6/2026 | A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting… | |
| Modificada | Alta (8.3) | 1.7% | — | Oracle Database Server | 18/1/2018 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks require human interaction… | |
| Modificada | Baja (2) | 0.89% | — | Oracle Database Server | 18/1/2018 | 17/6/2026 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, and 12.2.0.1. Difficult to exploit vulnerability allows high privileged attacker having Local Logon privilege with network access via multiple protocols to compromise Core RDBMS. Successful… | |
| Modificada | Crítica (9.1) | 1.7% | — | Oracle Database Server | 18/1/2018 | 17/6/2026 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromise Core RDBMS. While… | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Advanced World Database Project Advanced World Database | 13/12/2017 | 17/6/2026 | Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter. | |
| Modificada | Media (5.3) | 1.3% | — | SAP Hana Database | 12/12/2017 | 17/6/2026 | The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid. | |
| Modificada | Alta (7.5) | 40% | 💥 PoC | OpensslDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+41 | 13/11/2017 | 17/6/2026 | A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections… | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Rowindex US ZIP Codes Database Script | 31/10/2017 | 17/6/2026 | US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter. | |
| Modificada | Alta (8.8) | 0.43% | — | Oracle Database | 19/10/2017 | 17/6/2026 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create session privilege with logon to the infrastructure where Core RDBMS executes to compromise Core… | |
| Modificada | Baja (2.3) | 0.36% | — | Oracle Database | 19/10/2017 | 17/6/2026 | Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create User privilege with logon to the infrastructure where RDBMS Security executes to compromise… | |
| Modificada | Media (6.5) | 1.3% | — | Oracle Database | 19/10/2017 | 17/6/2026 | Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with logon to the infrastructure where XML Database executes to compromise XML Database.… | |
| Modificada | Alta (8.2) | 0.40% | — | Oracle Database | 19/10/2017 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Session, Create Procedure privilege with logon to the infrastructure where Java VM executes to… | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+54 | 4/10/2017 | 25/8/2026 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP… | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Xnau Participants Database | 4/9/2017 | 17/6/2026 | The Participants Database plugin before 1.7.5.10 for WordPress has XSS. | |
| Modificada | Crítica (9.9) | 2.3% | — | Oracle Database | 8/8/2017 | 17/6/2026 | Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. While… |