Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
599 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Network Integrity+24 | 25/6/2018 | 17/6/2026 | Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not… | |
| Modificada | Media (5.9) | 2.7% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Diameter Signaling Router+29 | 25/6/2018 | 25/8/2026 | Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a… | |
| Modificada | Media (6.5) | 3.0% | — | Vmware Spring FrameworkRedhat OpenshiftOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+26 | 11/5/2018 | 17/6/2026 | Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that… | |
| Modificada | Media (5.4) | 0.89% | — | Oracle Communications Unified Inventory Management | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Communications Unified Inventory Management component of Oracle Communications Applications (subcomponent: Portal). Supported versions that are affected are 7.2.4.2.x and 7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.3) | 1.1% | — | Oracle Communications Unified Inventory Management | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Communications Unified Inventory Management component of Oracle Communications Applications (subcomponent: Portal). Supported versions that are affected are 7.2.4.2.x and 7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Crítica (9.8) | 7.7% | 💥 Exploit | Savsofteproducts Phpinventory | 31/10/2017 | 17/6/2026 | Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+54 | 4/10/2017 | 25/8/2026 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP… | |
| Modificada | Media (6.4) | 1.2% | — | Oracle Hospitality Inventory Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Inventory Management component of Oracle Hospitality Applications (subcomponent: Inventory and Count Cycle). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (5.4) | 1.2% | — | Oracle Hospitality Inventory Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Inventory Management component of Oracle Hospitality Applications (subcomponent: Settings and Config). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Crítica (9.8) | 2.2% | — | IBM Bigfix InventoryIBM License Metric Tool | 13/7/2017 | 17/6/2026 | IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853. | |
| Modificada | Media (5.9) | 1.3% | — | IBM Bigfix Inventory | 26/4/2017 | 17/6/2026 | IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 118851. | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Media (5.3) | 1.1% | — | IBM License Metric ToolIBM Bigfix Inventory | 1/2/2017 | 17/6/2026 | IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system. | |
| Modificada | Media (5.5) | 0.31% | — | IBM License Metric ToolIBM Bigfix Inventory | 1/2/2017 | 17/6/2026 | IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user. | |
| Modificada | Media (5.5) | 0.31% | — | IBM License Metric ToolIBM Bigfix Inventory | 1/2/2017 | 17/6/2026 | IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user. | |
| Modificada | Media (5.5) | 0.32% | — | IBM License Metric ToolIBM Bigfix Inventory | 1/2/2017 | 17/6/2026 | IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system. | |
| Modificada | Alta (8.1) | 1.5% | — | IBM License Metric ToolIBM Bigfix Inventory | 1/2/2017 | 17/6/2026 | IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. | |
| Modificada | Media (5.9) | 1.2% | — | IBM License Metric ToolIBM Bigfix Inventory | 1/2/2017 | 17/6/2026 | IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Modificada | Media (6.1) | 0.85% | — | IBM License Metric ToolIBM Bigfix Inventory | 1/2/2017 | 17/6/2026 | IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to… | |
| Modificada | Alta (8.8) | 2.4% | — | HP Discovery AND Dependency Mapping Inventory | 8/6/2016 | 17/6/2026 | HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | |
| Modificada | Crítica (9.8) | 41% | — | Apache GroovyOracle Health Sciences Clinical Development CenterOracle Retail Order Broker Cloud ServiceOracle Retail Service Backbone+2 | 13/8/2015 | 17/6/2026 | The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object. | |
| Modificada | Media (4.3) | 2.3% | — | Ocsinventory-ng Ocsinventory NG | 7/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the OCS Reports Web Interface in OCS Inventory NG allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 5.1% | 💥 Exploit | Ocsinventory-ng OCS Inventory NG | 21/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 2.5% | — | HP Discovery&dependency Mapping Inventory | 25/3/2011 | 16/6/2026 | HP Discovery & Dependency Mapping Inventory (DDMI) 7.50, 7.51, 7.60, 7.61, 7.70, and 9.30 launches the Windows SNMP service with its default configuration, which allows remote attackers to obtain potentially sensitive information or have unspecified other impact by leveraging the public read community. | |
| Modificada | Media (4.3) | 1.7% | — | HP Discovery&dependency Mapping Inventory | 22/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.6x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |