Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

872 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)78%💥 ExploitFlexense DupscoutFlexense DisksavvyFlexense SyncbreezeFlexense Diskpulse24/1/201817/6/2026
A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server component. Successful exploitation of the…
ModificadaCrítica (9.8)19%💥 ExploitFlexible Poll Project Flexible Poll24/1/201817/6/2026
SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.
ModificadaAlta (8.1)9.0%💥 ExploitFlexense Sysgauge23/1/201817/6/2026
The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system-level access because of a Buffer Overflow.
ModificadaMedia (6.1)1.1%—Oracle Flexcube Direct Banking18/1/201817/6/2026
Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Logoff). Supported versions that are affected are 12.0.2 and 12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Direct…
ModificadaAlta (8.1)2.0%—Oracle Flexcube Universal Banking18/1/201817/6/2026
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker…
ModificadaAlta (8.8)1.7%—Oracle Flexcube Universal Banking18/1/201817/6/2026
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker…
ModificadaMedia (5.4)0.91%—Oracle Flexcube Universal Banking18/1/201817/6/2026
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Security Management System). Supported versions that are affected are 11.5.0, 11.6.0 and 11.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
ModificadaMedia (5.3)1.2%—Oracle Flexcube Universal Banking18/1/201817/6/2026
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 and 12.4.0. Difficult to exploit vulnerability allows low privileged…
ModificadaCrítica (9.8)39%💥 ExploitFlexense Diskboss12/1/201817/6/2026
A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged account.
ModificadaAlta (7.5)9.1%💥 ExploitFlexense Diskboss10/1/201817/6/2026
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.
ModificadaAlta (7.5)9.1%💥 ExploitFlexense Syncbreeze10/1/201817/6/2026
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9121.
ModificadaAlta (7.5)13%💥 ExploitFlexense Disk Pulse10/1/201817/6/2026
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9120.
ModificadaAlta (7.5)9.1%💥 ExploitFlexense VX Search10/1/201817/6/2026
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9123.
ModificadaAlta (7.5)3.8%💥 ExploitFlexense Sysgauge28/12/201717/6/2026
In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9221.
ModificadaCrítica (9.8)21%—Apache Flex BlazedsHP XP Command View Advanced Edition28/12/201717/6/2026
Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. During the deserialization process code is executed that for several known types has undesired side-effects. Other, unknown types may also exhibit such behaviors. One…
ModificadaAlta (7.5)7.0%💥 ExploitFlexense Syncbreeze19/12/201717/6/2026
The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds when reading server requests in the Host header on making a connection, resulting in a classic Buffer Overflow that causes a Denial of Service.
ModificadaAlta (7.8)12%💥 PoCFlexense Syncbreeze3/12/201717/6/2026
There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16. When sending a GET request with an excessive length, it is possible for a malicious user to overwrite the SEH record and execute a payload that would run under the Windows SYSTEM…
ModificadaMedia (6)0.33%—Cisco Hyperflex HX Data Platform16/11/201717/6/2026
A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local attacker to view sensitive information that should be restricted in the system log files. The attacker would have to be authenticated as an administrative user to conduct this…
ModificadaAlta (7.8)5.5%💥 ExploitFlexense Syncbreeze31/10/201717/6/2026
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The flaw is triggered by providing a long input into the "Destination directory" field, either within an XML document or through use of passive mode.
ModificadaAlta (7.1)1.6%—Oracle Flexcube Universal Banking19/10/201717/6/2026
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Security). Supported versions that are affected are 11.3, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with…
ModificadaMedia (5.6)0.93%—Prominent Multiflex M10a Controller Firmware17/10/201717/6/2026
A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The log out function in the application removes the user's session only on the client side. This may allow an attacker to bypass protection mechanisms, gain privileges, or assume the identity of…
ModificadaAlta (8.8)0.64%—Prominent Multiflex M10a Controller Firmware17/10/201717/6/2026
A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify requests, making it susceptible to cross-site request forgery. This may allow an attacker to execute unauthorized code, resulting in changes to the configuration of the…
ModificadaMedia (6.5)0.73%—Prominent Multiflex M10a Controller Firmware17/10/201717/6/2026
An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated user uses the Change Password feature on the application, the current password for the user is specified in plaintext. This may allow an attacker who has been authenticated to gain access to the…
ModificadaMedia (5.6)0.91%—Prominent Multiflex M10a Controller Firmware17/10/201717/6/2026
An Insufficient Session Expiration issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The user's session is available for an extended period beyond the last activity, allowing an attacker to reuse an old session for authorization.
ModificadaAlta (8.8)1.4%—Prominent Multiflex M10a Controller Firmware17/10/201717/6/2026
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is authenticated could change a user's password, enabling future access and possible…
Orbitaley — Vulnerabilidades