Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.0% | — | Oracle Weblogic Server | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.… | |
| Modificada | Media (5.7) | 0.24% | — | Oracle Weblogic Server | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle WebLogic Server… | |
| Modificada | Media (6.5) | 0.85% | — | Oracle Weblogic Server | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.… | |
| Modificada | Media (6.1) | 0.64% | — | Mogublog Project Mogublog | 12/7/2022 | 17/6/2026 | Mogu blog 5.2 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Crítica (9.8) | 1.00% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Improper Input Validation Vulnerability. | |
| Modificada | Crítica (9.8) | 0.51% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability. | |
| Modificada | Crítica (9.8) | 1.0% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability. | |
| Modificada | Crítica (9.8) | 0.72% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability. | |
| Modificada | Alta (8.1) | 0.78% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Random Values Vulnerability. | |
| Modificada | Crítica (9.8) | 1.2% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, contain an Improper Input Validation Vulnerability. | |
| Modificada | Crítica (9.8) | 1.2% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability. | |
| Modificada | Media (4.3) | 0.57% | — | Zhyd Oneblog | 23/6/2022 | 17/6/2026 | OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module. | |
| Modificada | Media (6.5) | 0.58% | — | Zhyd Oneblog | 23/6/2022 | 17/6/2026 | Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges. | |
| Modificada | Media (4.3) | 0.57% | — | Zhyd Oneblog | 23/6/2022 | 17/6/2026 | OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls. | |
| Modificada | Media (5.4) | 0.30% | — | Sideblog Project Sideblog | 13/6/2022 | 17/6/2026 | The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping | |
| Modificada | Media (4.3) | 0.45% | — | Easy Blog Project Easy Blog | 13/6/2022 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthenticated attacker to hijack the authentication of the administrator and delete a blog article or a category via a specially crafted page. | |
| Modificada | Crítica (9.8) | 2.0% | — | Responsive Online Blog Project Responsive Online Blog | 2/6/2022 | 17/6/2026 | Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Dell Bsafe Micro-edition-suiteOracle DatabaseOracle Http ServerOracle Security Service+1 | 1/6/2022 | 17/6/2026 | Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability. | |
| Modificada | Alta (7.5) | 0.69% | — | Dell Bsafe Micro-edition-suiteOracle Http ServerOracle Security ServiceOracle Weblogic Server Proxy Plug-in | 1/6/2022 | 17/6/2026 | Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability. | |
| Modificada | Media (5.4) | 0.88% | — | Simple Blog Project Simple Blog | 23/5/2022 | 17/6/2026 | The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur. | |
| Modificada | Media (6.5) | 0.74% | — | Blogengine.net | 18/5/2022 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting web server. | |
| Modificada | Crítica (9.1) | 2.7% | — | Blogengine.net | 13/5/2022 | 17/6/2026 | BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request. | |
| Modificada | Crítica (9.8) | 1.4% | — | Fantastic Blog Project Fantastic Blog | 4/5/2022 | 17/6/2026 | A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters. |