Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
614 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 7.9% | 💥 Exploit | Webiness Inventory Project Webiness Inventory | 14/5/2019 | 17/6/2026 | An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the creation of a new product. Consequently, an attacker can steal information from the site with the help of an installed executable file, or change the contents of pages. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Alta (7.5) | 1.8% | — | Fusioninventory | 29/3/2019 | 17/6/2026 | The FusionInventory plugin before 1.4 for GLPI 9.3.x and before 1.1 for GLPI 9.4.x mishandles sendXML actions. | |
| Modificada | Alta (8.8) | 5.0% | — | Ocsinventory-ng Ocsinventory NG | 29/11/2018 | 17/6/2026 | Unrestricted file upload (with remote code execution) in OCS Inventory NG ocsreports allows a privileged user to gain access to the server via crafted HTTP requests. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Bakeshop Inventory System Project Bakeshop Inventory System | 16/11/2018 | 17/6/2026 | Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb. | |
| Modificada | Crítica (9.8) | 2.3% | — | Webiness Project Webiness Inventory | 29/10/2018 | 17/6/2026 | Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter. | |
| Modificada | Alta (7.5) | 9.2% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Communications BRM - Elastic Charging EngineOracle Communications Converged Application Server - Service Controller+36 | 18/10/2018 | 25/8/2026 | Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an… | |
| Modificada | Alta (8.8) | 3.7% | — | Ocsinventory-ng OCS Inventory Server | 6/8/2018 | 17/6/2026 | Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template file containing PHP code, because file extensions other than .html are permitted. | |
| Modificada | Crítica (9.1) | 3.1% | — | Ocsinventory-ng Ocsinventory NG | 4/8/2018 | 17/6/2026 | OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service. | |
| Modificada | Alta (8.8) | 3.2% | — | Ocsinventory-ng Ocsinventory NG | 4/8/2018 | 17/6/2026 | OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. Authentication is needed in order to exploit this vulnerability. | |
| Modificada | Alta (8.8) | 1.3% | — | Ocsinventory-ng Ocsinventory NG | 4/8/2018 | 17/6/2026 | OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit the issues. | |
| Modificada | Alta (8) | 1.1% | — | Symantec Inventory | 25/7/2018 | 17/6/2026 | The Inventory Plugin for Symantec Management Agent prior to 7.6 POST HF7, 8.0 POST HF6, or 8.1 RU7 may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels. | |
| Modificada | Media (6.5) | 1.0% | — | Ocsinventory-ng Ocsinventory NG | 26/6/2018 | 17/6/2026 | OCS Inventory NG ocsreports 2.4 and ocsreports 2.3.1 version 2.4 and 2.3.1 contains a SQL Injection vulnerability in web search that can result in An authenticated attacker is able to gain full access to data stored within database. This attack appear to be exploitable via By sending crafted requests it is possible to… | |
| Modificada | Media (6.1) | 0.73% | — | Ocsinventory-ng Ocsinventory NG | 26/6/2018 | 17/6/2026 | OCS Inventory OCS Inventory NG version ocsreports 2.4 contains a Cross Site Scripting (XSS) vulnerability in login form and search functionality that can result in An attacker is able to execute arbitrary (javascript) code within a victims' browser. This attack appear to be exploitable via Victim must open a crafted… | |
| Modificada | Alta (7.5) | 3.2% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Network Integrity+24 | 25/6/2018 | 17/6/2026 | Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not… | |
| Modificada | Media (5.9) | 2.7% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Diameter Signaling Router+29 | 25/6/2018 | 25/8/2026 | Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a… | |
| Modificada | Media (6.5) | 3.0% | — | Vmware Spring FrameworkRedhat OpenshiftOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+26 | 11/5/2018 | 17/6/2026 | Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that… | |
| Modificada | Media (5.4) | 0.89% | — | Oracle Communications Unified Inventory Management | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Communications Unified Inventory Management component of Oracle Communications Applications (subcomponent: Portal). Supported versions that are affected are 7.2.4.2.x and 7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.3) | 1.1% | — | Oracle Communications Unified Inventory Management | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Communications Unified Inventory Management component of Oracle Communications Applications (subcomponent: Portal). Supported versions that are affected are 7.2.4.2.x and 7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Crítica (9.8) | 7.7% | 💥 Exploit | Savsofteproducts Phpinventory | 31/10/2017 | 17/6/2026 | Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+54 | 4/10/2017 | 25/8/2026 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP… | |
| Modificada | Media (6.4) | 1.2% | — | Oracle Hospitality Inventory Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Inventory Management component of Oracle Hospitality Applications (subcomponent: Inventory and Count Cycle). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (5.4) | 1.2% | — | Oracle Hospitality Inventory Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Inventory Management component of Oracle Hospitality Applications (subcomponent: Settings and Config). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Crítica (9.8) | 2.2% | — | IBM Bigfix InventoryIBM License Metric Tool | 13/7/2017 | 17/6/2026 | IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853. | |
| Modificada | Media (5.9) | 1.3% | — | IBM Bigfix Inventory | 26/4/2017 | 17/6/2026 | IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 118851. |