Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

614 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)7.9%💥 ExploitWebiness Inventory Project Webiness Inventory14/5/201917/6/2026
An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the creation of a new product. Consequently, an attacker can steal information from the site with the help of an installed executable file, or change the contents of pages.
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaAlta (7.5)1.8%—Fusioninventory29/3/201917/6/2026
The FusionInventory plugin before 1.4 for GLPI 9.3.x and before 1.1 for GLPI 9.4.x mishandles sendXML actions.
ModificadaAlta (8.8)5.0%—Ocsinventory-ng Ocsinventory NG29/11/201817/6/2026
Unrestricted file upload (with remote code execution) in OCS Inventory NG ocsreports allows a privileged user to gain access to the server via crafted HTTP requests.
ModificadaCrítica (9.8)3.2%💥 ExploitBakeshop Inventory System Project Bakeshop Inventory System16/11/201817/6/2026
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
ModificadaCrítica (9.8)2.3%—Webiness Project Webiness Inventory29/10/201817/6/2026
Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter.
ModificadaAlta (7.5)9.2%—Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Communications BRM - Elastic Charging EngineOracle Communications Converged Application Server - Service Controller+3618/10/201825/8/2026
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an…
ModificadaAlta (8.8)3.7%—Ocsinventory-ng OCS Inventory Server6/8/201817/6/2026
Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template file containing PHP code, because file extensions other than .html are permitted.
ModificadaCrítica (9.1)3.1%—Ocsinventory-ng Ocsinventory NG4/8/201817/6/2026
OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.
ModificadaAlta (8.8)3.2%—Ocsinventory-ng Ocsinventory NG4/8/201817/6/2026
OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. Authentication is needed in order to exploit this vulnerability.
ModificadaAlta (8.8)1.3%—Ocsinventory-ng Ocsinventory NG4/8/201817/6/2026
OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit the issues.
ModificadaAlta (8)1.1%—Symantec Inventory25/7/201817/6/2026
The Inventory Plugin for Symantec Management Agent prior to 7.6 POST HF7, 8.0 POST HF6, or 8.1 RU7 may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
ModificadaMedia (6.5)1.0%—Ocsinventory-ng Ocsinventory NG26/6/201817/6/2026
OCS Inventory NG ocsreports 2.4 and ocsreports 2.3.1 version 2.4 and 2.3.1 contains a SQL Injection vulnerability in web search that can result in An authenticated attacker is able to gain full access to data stored within database. This attack appear to be exploitable via By sending crafted requests it is possible to…
ModificadaMedia (6.1)0.73%—Ocsinventory-ng Ocsinventory NG26/6/201817/6/2026
OCS Inventory OCS Inventory NG version ocsreports 2.4 contains a Cross Site Scripting (XSS) vulnerability in login form and search functionality that can result in An attacker is able to execute arbitrary (javascript) code within a victims' browser. This attack appear to be exploitable via Victim must open a crafted…
ModificadaAlta (7.5)3.2%—Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Network Integrity+2425/6/201817/6/2026
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not…
ModificadaMedia (5.9)2.7%—Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Diameter Signaling Router+2925/6/201825/8/2026
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a…
ModificadaMedia (6.5)3.0%—Vmware Spring FrameworkRedhat OpenshiftOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+2611/5/201817/6/2026
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that…
ModificadaMedia (5.4)0.89%—Oracle Communications Unified Inventory Management18/1/201817/6/2026
Vulnerability in the Oracle Communications Unified Inventory Management component of Oracle Communications Applications (subcomponent: Portal). Supported versions that are affected are 7.2.4.2.x and 7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (6.3)1.1%—Oracle Communications Unified Inventory Management18/1/201817/6/2026
Vulnerability in the Oracle Communications Unified Inventory Management component of Oracle Communications Applications (subcomponent: Portal). Supported versions that are affected are 7.2.4.2.x and 7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaCrítica (9.8)7.7%💥 ExploitSavsofteproducts Phpinventory31/10/201717/6/2026
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
AnalizadaAlta (8.1)100%⚠ Explotación activa💥 ExploitApache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+544/10/201725/8/2026
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP…
ModificadaMedia (6.4)1.2%—Oracle Hospitality Inventory Management8/8/201717/6/2026
Vulnerability in the Oracle Hospitality Inventory Management component of Oracle Hospitality Applications (subcomponent: Inventory and Count Cycle). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
ModificadaMedia (5.4)1.2%—Oracle Hospitality Inventory Management8/8/201717/6/2026
Vulnerability in the Oracle Hospitality Inventory Management component of Oracle Hospitality Applications (subcomponent: Settings and Config). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaCrítica (9.8)2.2%—IBM Bigfix InventoryIBM License Metric Tool13/7/201717/6/2026
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853.
ModificadaMedia (5.9)1.3%—IBM Bigfix Inventory26/4/201717/6/2026
IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 118851.
Orbitaley — Vulnerabilidades