Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 7.8% | 💥 Exploit | Opentext Documentum Content Server | 13/10/2017 | 17/6/2026 | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE RPC-command, which allows any authenticated user to hijack an arbitrary file from the Content Server filesystem; because some files on the Content Server filesystem are… | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+54 | 4/10/2017 | 25/8/2026 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP… | |
| Modificada | Crítica (9.8) | 1.3% | — | Opentext Document Sciences Xpression | 3/10/2017 | 17/6/2026 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to an XML External Entity vulnerability: /xFramework/services/QuickDoc.QuickDocHttpSoap11Endpoint/. An unauthenticated user is able to read directory listings or system… | |
| Modificada | Alta (8.8) | 2.7% | 💥 Exploit | Opentext Document Sciences Xpression | 3/10/2017 | 17/6/2026 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId. In order for this vulnerability to be exploited, an attacker must authenticate to the… | |
| Modificada | Alta (8.8) | 1.9% | 💥 Exploit | Opentext Document Sciences Xpression | 3/10/2017 | 17/6/2026 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order for this vulnerability to be exploited, an attacker must… | |
| Modificada | Media (6.1) | 0.66% | — | Opentext Document Sciences Xpression | 3/10/2017 | 17/6/2026 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/Deployment (cat_id). | |
| Modificada | Media (6.1) | 0.66% | — | Opentext Document Sciences Xpression | 3/10/2017 | 17/6/2026 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/XPressoDoc, parameter: categoryId. | |
| Modificada | Media (6.5) | 1.3% | — | Opentext Document Sciences Xpression | 3/10/2017 | 17/6/2026 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Arbitrary File Read: /xAdmin/html/cm_datasource_group_xsd.jsp, parameter: xsd_datasource_schema_file filename. In order for this vulnerability to be exploited, an… | |
| Modificada | Media (6.1) | 1.1% | — | Blogotext Project Blogotext | 2/10/2017 | 17/6/2026 | Stored XSS vulnerability via a comment in inc/conv.php in BlogoText before 3.7.6 allows an unauthenticated attacker to inject JavaScript. If the victim is an administrator, an attacker can (for example) change global settings or create/delete posts. It is also possible to execute JavaScript against unauthenticated… | |
| Modificada | Alta (8.8) | 1.4% | — | Opentext Documentum AdministratorOpentext Documentum Webtop | 28/9/2017 | 17/6/2026 | Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving unspecified… | |
| Modificada | Alta (8.8) | 1.2% | — | Opentext Documentum AdministratorOpentext Documentum Webtop | 28/9/2017 | 17/6/2026 | Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving… | |
| Modificada | Media (6.1) | 0.83% | — | Opentext Documentum AdministratorOpentext Documentum Webtop | 28/9/2017 | 17/6/2026 | Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the… | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | Opentext Documentum AdministratorOpentext Documentum Webtop | 28/9/2017 | 17/6/2026 | Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain… | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatNetapp 7-mode Transition ToolNetapp Oncommand BalanceNetapp Oncommand Shift+18 | 19/9/2017 | 6/8/2026 | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed… | |
| Modificada | Alta (7.8) | 0.91% | — | Sublimetext Sublime Text 3 | 5/7/2017 | 17/6/2026 | Sublime Text 3 Build 3126 allows user-assisted attackers to cause a denial of service or possibly have unspecified other impact via a crafted .mkv file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands, as demonstrated by Ctrl-A, Delete,… | |
| Modificada | Crítica (9.8) | 4.8% | — | Cisco Context Service Development KIT | 13/6/2017 | 17/6/2026 | A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthenticated, remote attacker to execute arbitrary code on the affected device with the privileges of the web server. More Information: CSCvb66730. Known Affected Releases: 2.0. | |
| Modificada | Media (5.3) | 3.5% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | |
| Modificada | Alta (7.3) | 4.2% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | |
| Modificada | Alta (7.5) | 17% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3… | |
| Modificada | Media (6.1) | 0.90% | — | Opentext Tempo BOX | 10/5/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in OpenText Tempo Box 10.0.3 allows remote attackers to inject arbitrary web script or HTML persistently via the name of an uploaded image. | |
| Modificada | Alta (8.8) | 4.2% | 💥 Exploit | Opentext Documentum Content Server | 25/4/2017 | 17/6/2026 | OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dm_bp_transition docbase method with a user-created dm_procedure object, as demonstrated by… | |
| Modificada | Alta (8.8) | 2.0% | — | Opentext Documentum Content Server | 21/4/2017 | 17/6/2026 | OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4532. | |
| Modificada | Alta (7.5) | 11% | — | NettyRedhat Jboss Data GridRedhat Jboss Middleware Text-only AdvisoriesApache Cassandra | 13/4/2017 | 17/6/2026 | handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop). | |
| Modificada | Alta (7.8) | 2.1% | — | Textract Project Textract | 6/4/2017 | 17/6/2026 | textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files. | |
| Modificada | Crítica (9.8) | 25% | 💥 Exploit | Opentext Documentum D2 | 22/2/2017 | 17/6/2026 | OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries. |