Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 85% | ⚠ Explotación activa💥 Exploit | JqueryDebian LinuxFedoraproject FedoraDrupal+48 | 29/4/2020 | 17/6/2026 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Media (6.1) | 1.0% | — | Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway | 15/4/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HRMS product of Oracle PeopleSoft (component: Candidate Gateway). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HRMS. Successful attacks require… | |
| Modificada | Media (4.3) | 0.83% | — | Oracle Peoplesoft Enterprise Human Capital Management Absence Management | 15/4/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Absence… | |
| Modificada | Media (6.5) | 0.75% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 27/2/2020 | 17/6/2026 | Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials. | |
| Modificada | Alta (7.1) | 0.71% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus ReadystartSiemens Nucleus Safetycert+22 | 16/1/2020 | 17/6/2026 | A vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8.2 < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.3), APOGEE PXC Modular (P2 Ethernet) (All versions >= V2.8.2… | |
| Modificada | Media (4.3) | 0.80% | — | Oracle Peoplesoft Enterprise Human Capital Management Human Resources | 15/1/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Company Dir / Org Chart Viewer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM… | |
| Modificada | Media (4.3) | 0.78% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 19/12/2019 | 17/6/2026 | Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins. | |
| Modificada | Media (4.3) | 1.1% | — | Oracle Peoplesoft Enterprise Human Capital Management Human Resources | 16/10/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: US Federal Specific). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Modificada | Alta (7.5) | 92% | 💥 Exploit | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+33 | 1/5/2019 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version… | |
| Modificada | Media (6.1) | 0.98% | — | Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway | 23/4/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: Candidate Gateway). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HRMS. Successful… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Peoplesoft Enterprise Human Capital Management Talent Acquisition Manager | 23/4/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager component of Oracle PeopleSoft Products (subcomponent: Job Opening). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Alta (7.5) | 1.3% | — | Cloudfoundry Capi-release | 17/4/2019 | 17/6/2026 | Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to create UAA clients and knowledge of the email of a victim in the foundation may escalate their privileges to that of the… | |
| Modificada | Alta (8.1) | 1.3% | — | Cloudfoundry Capi-release | 13/3/2019 | 17/6/2026 | Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service. | |
| Modificada | Media (6.1) | 1.1% | — | Oracle Peoplesoft Enterprise Human Capital Management Eprofile Manager Desktop | 16/1/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM eProfile Manager Desktop component of Oracle PeopleSoft Products (subcomponent: Guided Self Service). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft… | |
| Modificada | Media (6.1) | 11% | 💥 PoC | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+34 | 2/8/2018 | 17/6/2026 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Peoplesoft Enterprise Human Capital Management Human Resources | 18/7/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources component of Oracle PeopleSoft Products (subcomponent: Compensation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Peoplesoft Enterprise Human Capital Management Shared Components | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Shared Components component of Oracle PeopleSoft Products (subcomponent: Notepad). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Alta (8.1) | 1.9% | — | Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged attacker with… | |
| Modificada | Alta (8.1) | 1.9% | — | Oracle Financial Services Basel Regulatory Capital Basic | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Basel Regulatory Capital Basic component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Financial Services Basel Regulatory Capital Basic | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Basel Regulatory Capital Basic component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (5.4) | 1.0% | — | Oracle Peoplesoft Enterprise Human Capital Management | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM. Successful attacks… | |
| Modificada | Media (5.3) | 0.97% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 18/4/2018 | 17/6/2026 | Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An application developer may create an application with a route that conflicts with a platform service route and receive traffic intended for the service. | |
| Modificada | Alta (8.1) | 1.1% | — | Cloudfoundry Capi-release | 27/3/2018 | 17/6/2026 | Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malicious user can predict the location of application blobs and leverage path traversal to create a malicious application that has the ability to overwrite arbitrary files on… |