Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.69% | — | Jenkins Testcomplete Support | 2/7/2020 | 17/6/2026 | Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Alta (7.2) | 1.1% | — | Turnkeylinux Support Incident Tracker | 26/6/2020 | 17/6/2026 | Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qbe.php criteriafield parameter. | |
| Modificada | Alta (7) | 56% | 💥 Exploit | Apache TomcatDebian LinuxOpensuse LeapFedoraproject Fedora+22 | 20/5/2020 | 25/8/2026 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is… | |
| Analizada | Media (6.1) | 85% | ⚠ Explotación activa💥 Exploit | JqueryDebian LinuxFedoraproject FedoraDrupal+48 | 29/4/2020 | 17/6/2026 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Media (4.7) | 0.36% | 💥 PoC | Intel Driver & Support Assistant | 15/4/2020 | 17/6/2026 | Race condition in the Intel(R) Driver and Support Assistant before version 20.1.5 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Isupport | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Mail). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Isupport | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Profile). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Isupport | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Admin). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Isupport | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Profile). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Isupport | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Profile). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction… | |
| Modificada | Media (4.7) | 1.0% | — | Oracle Isupport | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks… | |
| Modificada | Alta (7.5) | 1.5% | — | Siemens DK Standard Ethernet ControllerSiemens Profinet DriverSiemens Simatic IPC SupportSiemens Ek-ertec 200 Firmware+48 | 11/2/2020 | 17/6/2026 | Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack.… | |
| Modificada | Media (4.7) | 1.0% | — | Oracle Isupport | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Others). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle iSupport. Successful attacks require… | |
| Modificada | Media (4.7) | 1.0% | — | Oracle Isupport | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Others). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle iSupport. Successful attacks require… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Isupport | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Others). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle iSupport. Successful attacks require… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Isupport | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Others). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle iSupport. Successful attacks require… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Isupport | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Others). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle iSupport. Successful attacks require… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Isupport | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Others). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle iSupport. Successful attacks require… | |
| Modificada | Media (4.8) | 0.72% | — | Getawesomesupport Awesome Support | 9/1/2020 | 17/6/2026 | The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter. | |
| Modificada | Media (6.1) | 0.67% | — | Sitracker Support Incident Tracker | 2/1/2020 | 17/6/2026 | In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CVE-2012-2235. | |
| Modificada | Media (6.1) | 0.67% | — | Sitracker Support Incident Tracker | 2/1/2020 | 17/6/2026 | In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS. | |
| Modificada | Media (6.1) | 0.67% | — | Sitracker Support Incident Tracker | 2/1/2020 | 17/6/2026 | In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload is, for example, executed on the about.php page. | |
| Modificada | Media (6.1) | 0.67% | — | Sitracker Support Incident Tracker | 2/1/2020 | 17/6/2026 | In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS. | |
| Modificada | Media (6.5) | 0.85% | — | Jenkins Alauda Kubernetes Support | 17/12/2019 | 17/6/2026 | A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kubernetes service account token or credentials stored in… | |
| Modificada | Alta (8.8) | 0.86% | — | Jenkins Alauda Kubernetes Support | 17/12/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kubernetes service account token or credentials stored in Jenkins. |