Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.5% | — | Oracle Retail Integration BUS | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Retail Integration Bus component in Oracle Retail Applications 13.0, 13.1, 13.2, 14.0, 14.1, and 15.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Install. | |
| Modificada | Alta (8.8) | 5.1% | — | Oracle DocumakerOracle Enterprise Manager OPS CenterOracle Health Sciences Information ManagerOracle Healthcare Master Person Index+7 | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index… | |
| Modificada | Media (5.3) | 1.5% | — | IBM Integration BUSIBM Websphere Message Broker | 2/7/2016 | 17/6/2026 | The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malformed POST request and then reading the Java stack trace. | |
| Modificada | Alta (7.5) | 1.4% | — | IBM B2B Advanced CommunicationsIBM Multi-enterprise Integration Gateway | 15/5/2016 | 17/6/2026 | IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Media (5.3) | 1.9% | — | IBM Integration BUSIBM Websphere Message Broker | 11/1/2016 | 17/6/2026 | IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to obtain sensitive information about the HTTP server via unspecified vectors. | |
| Modificada | Media (4.3) | 0.97% | — | IBM B2B Advanced CommunicationsIBM Multi-enterprise Integration Gateway | 1/1/2016 | 17/6/2026 | IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.x before 1.0.0.4, when guest access is configured, allow remote authenticated users to obtain sensitive information by reading error messages in responses. | |
| Modificada | Media (5) | 0.97% | — | SAP Manufacturing Integration AND Intelligence | 24/11/2015 | 17/6/2026 | SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade attacks and decrypt passwords via unspecified vectors, aka SAP Security Note 2240274. | |
| Modificada | Baja (3.2) | 0.33% | — | IBM Websphere Message BrokerIBM Integration BUS | 26/10/2015 | 17/6/2026 | IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command. | |
| Modificada | Media (5) | 2.3% | — | Pentaho Data IntegrationPentaho Business Analytics | 22/9/2015 | 17/6/2026 | The GetResource servlet in Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x, and 5.0.x through 5.2.x and Pentaho Data Integration (PDI) Suite 4.3.x, 4.4.x, and 5.0.x through 5.2.x does not restrict access to files in the pentaho-solutions/system folder, which allows remote attackers to obtain passwords and other… | |
| Modificada | Baja (3.5) | 0.87% | — | IBM Integration BUSIBM Websphere Message Broker | 23/8/2015 | 17/6/2026 | IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5.8) | 1.8% | — | Chamilo Integration Project Chamilo Integration | 18/8/2015 | 17/6/2026 | Open redirect vulnerability in the Chamilo integration module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Websphere Message BrokerIBM Integration BUS | 28/6/2015 | 17/6/2026 | IBM WebSphere Message Broker Toolkit 7 before 7007 IF2 and 8 before 8005 IF1 and Integration Toolkit 9 before 9003 IF1 are distributed with MQ client JAR files that support only weak TLS ciphers, which might make it easier for remote attackers to obtain sensitive information by sniffing the network during a connection… | |
| Modificada | Baja (3.5) | 0.95% | — | Ubercart Webform Integration Project Ubercart Webform Integration | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Ubercart Webform Integration module before 6.x-1.8 and 7.x before 7.x-2.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 0.89% | — | Phplist Integration Project Phplist Integration | 21/4/2015 | 17/6/2026 | SQL injection vulnerability in the PHPlist Integration Module before 6.x-1.7 for Drupal allows remote administrators to execute arbitrary SQL commands via unspecified vectors, related to the "phpList database." | |
| Modificada | Media (5) | 1.4% | — | IBM Integration BUSIBM Websphere Message Broker | 2/2/2015 | 17/6/2026 | The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault. | |
| Modificada | Media (5.8) | 2.0% | — | NYU Opensso Integration | 2/1/2015 | 17/6/2026 | Open redirect vulnerability in the logon page in NYU OpenSSO Integration 2.1 and earlier for Ex Libris Patron Directory Services (PDS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter. | |
| Modificada | Media (4.3) | 0.93% | — | NYU Opensso Integration | 2/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the logon page in NYU OpenSSO Integration 2.1 and earlier for Ex Libris Patron Directory Services (PDS) allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |
| Modificada | Media (5) | 6.8% | 💥 Exploit | Videowhisper Live Streaming Integration | 29/12/2014 | 17/6/2026 | The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message. | |
| Modificada | Alta (10) | 9.8% | 💥 Exploit | Videowhisper Live Streaming Integration | 29/12/2014 | 17/6/2026 | Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, and then accessing the file via a direct request to a… | |
| Modificada | Media (4.3) | 0.95% | — | IBM Rational Lifecycle Integration Adapter FOR Windchill | 12/12/2014 | 17/6/2026 | Session fixation vulnerability in IBM Rational Lifecycle Integration Adapter for Windchill 1.x before 1.0.1 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (4.3) | 1.6% | — | Contactus Contact Form 7 Integrations | 26/9/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in includes/toAdmin.php in Contact Form 7 Integrations plugin 1.0 through 1.3.10 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) uE or (2) uC parameter. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Integration BUS Manufacturing Pack | 18/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Integration Bus Manufacturing Pack 1.x before 1.0.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | IBM Websphere Message BrokerIBM Integration BUS | 18/9/2014 | 17/6/2026 | The web user interface in IBM WebSphere Message Broker 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.3 allows remote authenticated users to obtain sensitive information by reading the error page. | |
| Modificada | Media (4.3) | 2.0% | — | Videowhisper Live Streaming Integration | 1/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | SAP BI Universal Data Integration | 10/4/2014 | 17/6/2026 | SQL injection vulnerability in SAP BI Universal Data Integration allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to the J2EE schema. |