Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

76 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.9%—Oracle Financial Services Basel Regulatory Capital Basic19/4/201817/6/2026
Vulnerability in the Oracle Financial Services Basel Regulatory Capital Basic component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
ModificadaMedia (6.1)1.4%—Oracle Financial Services Basel Regulatory Capital Basic19/4/201817/6/2026
Vulnerability in the Oracle Financial Services Basel Regulatory Capital Basic component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
ModificadaMedia (5.4)1.0%—Oracle Peoplesoft Enterprise Human Capital Management19/4/201817/6/2026
Vulnerability in the PeopleSoft Enterprise HCM component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM. Successful attacks…
ModificadaMedia (5.4)0.83%—Oracle Peoplesoft Enterprise Human Capital Management Human Resources18/1/201817/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Human Resources component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human…
ModificadaMedia (6.1)1.1%—Oracle Peoplesoft Enterprise Human Capital Management Human Resources18/1/201817/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Human Resources component of Oracle PeopleSoft Products (subcomponent: Company Dir / Org Chart Viewer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft…
ModificadaMedia (4.6)1.0%—Oracle Peoplesoft Enterprise Human Capital Management Human Resources19/10/201717/6/2026
Vulnerability in the PeopleSoft Enterprise HCM component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM. Successful attacks…
ModificadaMedia (5.4)1.0%—Oracle Peoplesoft Enterprise Human Capital Management Human Resources19/10/201717/6/2026
Vulnerability in the PeopleSoft Enterprise HCM component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM. Successful attacks…
ModificadaMedia (4.3)1.3%—Oracle Peoplesoft Enterprise Human Capital Management Eperformance27/1/201717/6/2026
Vulnerability in the PeopleSoft Enterprise HCM ePerformance component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM ePerformance.…
ModificadaMedia (6.1)0.97%—EMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum TaskspaceEMC Documentum Webtop23/1/201717/6/2026
EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version 6.7SP3, prior to P02; and EMC Documentum Capital Projects Version 1.9, prior to P30 and Version 1.10, prior to P17; and EMC Documentum Administrator Version 7.0, Version 7.1, and Version 7.2 prior to…
ModificadaMedia (4.3)1.7%—Oracle Peoplesoft Enterprise Human Capital Management Time AND Labor25/10/201617/6/2026
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality via unknown vectors.
ModificadaMedia (4.2)1.4%—Oracle Peoplesoft Enterprise Human Capital Management Talent Acquisition Manager25/10/201617/6/2026
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Talent Acquisition Manager.
ModificadaMedia (4.8)1.00%—Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway25/10/201617/6/2026
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote administrators to affect confidentiality and integrity via vectors related to Candidate Gateway.
ModificadaMedia (5.9)0.57%—Misys Fusioncapital Opics Plus19/7/201617/6/2026
Misys FusionCapital Opics Plus does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)1.6%—Misys Fusioncapital Opics Plus19/7/201617/6/2026
Misys FusionCapital Opics Plus allows remote authenticated users to gain privileges via a man-in-the-middle attack that modifies the xmlMessageOut parameter.
ModificadaMedia (6.5)1.1%—Misys Fusioncapital Opics Plus19/7/201617/6/2026
Multiple SQL injection vulnerabilities in Misys FusionCapital Opics Plus allow remote authenticated users to execute arbitrary SQL commands via the (1) ID or (2) Branch parameter.
ModificadaMedia (6.3)1.3%—EMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum TaskspaceEMC Documentum Webtop23/6/201617/6/2026
EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated users to bypass intended access restrictions and execute arbitrary…
ModificadaMedia (5.4)1.0%—Oracle Peoplesoft Enterprise Human Capital Management Eperformance21/4/201617/6/2026
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to ePerformance.
ModificadaMedia (4.6)0.88%—Oracle Peoplesoft Enterprise Human Capital Management Eperformance21/4/201617/6/2026
Unspecified vulnerability in the PeopleSoft Enterprise HCM ePerformance component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Security.
ModificadaMedia (6.5)1.5%—Oracle Peoplesoft Enterprise Human Capital Management Human Resources21/4/201617/6/2026
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via vectors related to Fusion HR Talent Integration.
ModificadaMedia (5)1.8%—Oracle Human Capital Management Configuration Workbench21/1/201617/6/2026
Unspecified vulnerability in the Oracle HCM Configuration Workbench component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors.
ModificadaMedia (5.4)0.27%—Sparkpay Capital ONE Spark11/9/201417/6/2026
The Capital One Spark Pay (aka com.capitalone.sparkpay) application 0.9.81 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.8)0.98%—EMC Digital Assets ManagerEMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum Records Manager+520/8/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hijack the authentication of arbitrary users.
ModificadaMedia (4.3)1.8%—EMC Digital Assets ManagerEMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum Webtop+420/8/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter.
ModificadaMedia (4.3)1.0%—EMC Documentum TaskspaceEMC Documentum Capital ProjectsEMC Documentum WDKEMC Documentum Digital Asset Manager+36/11/201316/6/2026
Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop before 6.7 SP2 P07, Documentum WDK before 6.7 SP2 P07, Documentum Taskspace before 6.7 SP2 P07, Documentum Records Manager before 6.7 SP2 P07, Documentum Web Publisher before 6.5 SP7, Documentum Digital Asset Manager before 6.5 SP6, Documentum…
ModificadaMedia (5.5)2.5%—Oracle ApexOracle Application ServerOracle Collaboration SuiteOracle Database Server+518/7/200716/6/2026
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims…
Orbitaley — Vulnerabilidades