Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.0% | — | Oracle Flexcube Investor Servicing | 23/7/2019 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Crítica (9.8) | 53% | 💥 Exploit | Flowpaper Flexpaper | 3/7/2019 | 17/6/2026 | The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. | |
| Modificada | Alta (7.2) | 18% | 💥 Exploit | Primasystems Flexair | 1/7/2019 | 17/6/2026 | Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system. | |
| Modificada | Alta (8.8) | 31% | — | Primasystems Flexair | 1/7/2019 | 17/6/2026 | Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application’s web root with root privileges. | |
| Modificada | Crítica (9.8) | 1.6% | — | Primasystems Flexair | 1/7/2019 | 17/6/2026 | Prima Systems FlexAir devices have Default Credentials. | |
| Modificada | Crítica (9.8) | 4.5% | — | Primasystems Flexair | 1/7/2019 | 17/6/2026 | Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable name, and an attacker can use brute force to identify the database backup file name. A malicious actor can exploit this issue to download the database file and disclose login information, which can… | |
| Modificada | Alta (8.8) | 15% | 💥 Exploit | Primasystems Flexair | 1/7/2019 | 17/6/2026 | Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password. | |
| Modificada | Alta (8.8) | 0.94% | — | Primasystems Flexair | 1/7/2019 | 17/6/2026 | Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website. | |
| Modificada | Alta (8.8) | 2.4% | — | Primasystems Flexair | 1/7/2019 | 17/6/2026 | Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication. | |
| Modificada | Alta (8.8) | 2.4% | — | Primasystems Flexair | 5/6/2019 | 17/6/2026 | Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow an authenticated attacker to escalate privileges. | |
| Modificada | Crítica (9) | 8.1% | 💥 Exploit | Primasystems Flexair | 5/6/2019 | 17/6/2026 | Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site. | |
| Modificada | Alta (8.8) | 11% | 💥 Exploit | Primasystems Flexair | 5/6/2019 | 17/6/2026 | Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an authenticated attacker to gain full system… | |
| Modificada | Alta (7.5) | 9.8% | — | Apache CamelOracle Enterprise Data QualityOracle Enterprise Manager Base PlatformOracle Flexcube Private Banking+1 | 28/5/2019 | 17/6/2026 | Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed. | |
| Modificada | Alta (7.5) | 92% | 💥 Exploit | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+33 | 1/5/2019 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version… | |
| Analizada | Alta (7.5) | 4.9% | 💥 PoC | Mchange C3p0Fedoraproject FedoraOracle Communications IP Service ActivatorOracle Communications Session Route Manager+7 | 22/4/2019 | 17/6/2026 | c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration. | |
| Modificada | Media (5.3) | 5.9% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+22 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path.… | |
| Modificada | Media (5.3) | 4.1% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+21 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in… | |
| Modificada | Media (6.1) | 9.4% | — | Eclipse JettyDebian LinuxApache ActivemqApache Drill+3 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents. | |
| Modificada | Alta (7.5) | 1.3% | — | Lenovo Flex System X240 M4 FirmwareLenovo Flex System X240 M5 FirmwareLenovo Flex System X280 X6 FirmwareLenovo Flex System X440 M4 Firmware+38 | 22/4/2019 | 17/6/2026 | In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support. | |
| Modificada | Crítica (9.8) | 5.6% | — | Rockwellautomation Powerflex 525 AC Drives Firmware | 4/4/2019 | 17/6/2026 | Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack. The vulnerability allows the attacker to crash the CIP in a way that it does not accept new connections, but keeps the current connections… | |
| Modificada | Alta (7.5) | 2.8% | — | Flexera Flexnet PublisherOracle Communications Lsms | 21/3/2019 | 17/6/2026 | A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and… | |
| Modificada | Alta (7.5) | 2.2% | — | Flexera Flexnet PublisherOracle Communications Lsms | 21/3/2019 | 17/6/2026 | A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the… | |
| Modificada | Alta (7.5) | 2.2% | — | Flexera Flexnet PublisherOracle Communications Lsms | 21/3/2019 | 17/6/2026 | A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and… | |
| Modificada | Crítica (9.8) | 3.7% | — | Flexera Flexnet PublisherOracle Communications Lsms | 25/2/2019 | 17/6/2026 | A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to… | |
| Modificada | Baja (3.3) | 0.17% | — | Cisco Hyperflex HX Data Platform | 21/2/2019 | 17/6/2026 | A vulnerability in the Graphite interface of Cisco HyperFlex software could allow an authenticated, local attacker to write arbitrary data to the Graphite interface. The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by connecting to the Graphite service and… |