Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.7) | 1.4% | — | Oracle Flexcube Direct Banking | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.3 allows remote authenticated users to affect confidentiality via vectors related to Accounts. | |
| Modificada | Media (6.1) | 1.2% | — | Oracle Flexcube Direct Banking | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to Pre-Login. | |
| Modificada | Crítica (9.1) | 2.8% | — | Oracle Flexcube Direct Banking | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to the Login sub-component. | |
| Modificada | Media (6.1) | 1.2% | — | Oracle Flexcube Direct Banking | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to Pre-Login. | |
| Modificada | Media (5) | 1.2% | — | Basware Banking | 31/8/2015 | 17/6/2026 | Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 due to different vulnerability types. NOTE: this vulnerability exists because… | |
| Modificada | Baja (2.1) | 0.57% | — | Basware Banking | 31/8/2015 | 17/6/2026 | Basware Banking (Maksuliikenne) before 8.90.07.X stores private keys in plaintext in the SQL database, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 due to different vulnerability types. | |
| Modificada | Media (4.6) | 0.33% | — | Basware Banking | 31/8/2015 | 17/6/2026 | Basware Banking (Maksuliikenne) 8.90.07.X relies on the client to enforce account locking, which allows local users to bypass that security mechanism by deleting the entry from the locking table. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability type and different… | |
| Modificada | Media (4.3) | 1.1% | — | Basware Banking | 31/8/2015 | 17/6/2026 | Basware Banking (Maksuliikenne) before 8.90.07.X relies on the client to enforce (1) login verification, (2) audit trail creation, and (3) account locking, which allows remote attackers to "disrupt security-critical functions" by "dropping network traffic." NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2… | |
| Modificada | Media (6.5) | 1.1% | — | Basware Banking | 31/8/2015 | 17/6/2026 | Basware Banking (Maksuliikenne) 8.90.07.X uses a hardcoded password for an unspecified account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability… | |
| Modificada | Media (6.5) | 1.2% | — | Basware Banking | 31/8/2015 | 17/6/2026 | Basware Banking (Maksuliikenne) before 8.90.07.X uses a hardcoded password for the ANCO account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability… | |
| Modificada | Media (5.8) | 0.53% | — | Basware Banking | 31/8/2015 | 17/6/2026 | Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryption keys, user credentials, and other sensitive information by sniffing the network or modify this traffic by inserting packets into the… | |
| Modificada | Baja (2.1) | 0.46% | — | Usaa Mobile Banking | 16/4/2015 | 17/6/2026 | The USAA Mobile Banking application before 7.10.1 for Android displays the most recently-used screen before prompting the user for login, which might allow physically proximate users to obtain banking account numbers and balances. | |
| Modificada | Media (5.4) | 0.27% | — | Santanderbank Santander Personal Banking | 2/10/2014 | 17/6/2026 | The Santander Personal Banking (aka com.sovereign.santander) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Woodforest Mobile Banking | 2/10/2014 | 17/6/2026 | The Woodforest Mobile Banking (aka com.woodforest) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Westpac Mobile Banking | 26/9/2014 | 17/6/2026 | The Westpac Mobile Banking (aka org.westpac.bank) application 5.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | DCU Mobile Banking | 18/9/2014 | 17/6/2026 | The DCU Mobile Banking (aka com.Vertifi.Mobile.P211391825) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Nonghyup Smart Nhibzbanking | 9/9/2014 | 17/6/2026 | The smart.nhibzbanking (aka nh.smart.nhibzbanking) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Gameinfo Best Racing/moto Games Ranking | 9/9/2014 | 17/6/2026 | The Best Racing/moto Games Ranking (aka com.subapp.android.racing) application 2.2.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Cibc Mobile Banking | 9/9/2014 | 17/6/2026 | The CIBC Mobile Banking (aka com.cibc.android.mobi) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 8.4% | — | Apache StrutsOracle Flexcube Private BankingOracle Mysql Enterprise MonitorOracle Webcenter Sites | 30/9/2013 | 16/6/2026 | Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Overseaswtc Nexorone Online Banking System | 8/2/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in login.php in NexorONE Online Banking allow remote attackers to inject arbitrary web script or HTML via the (1) visitor_language parameter to register.php or (2) message parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Instantrankingseo Infocus Real Estate | 3/5/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote attackers to execute arbitrary SQL commands via the (1) username (aka login) and (2) password parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Craftsilicon Banking@home | 25/2/2009 | 16/6/2026 | SQL injection vulnerability in Login.asp in Craft Silicon Banking@Home 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginName parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Phpscripts Ranking-script | 9/2/2009 | 16/6/2026 | phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Minbank Micronation Banking System | 30/1/2009 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Micronation Banking System (minba) 1.5.0 allow remote attackers to execute arbitrary PHP code via a URL in the minsoft_path parameter to (1) utdb_access.php and (2) utgn_message.php in utility/. |