Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
524 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 23/10/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_withdraw_money.php. The manipulation of the argument account_number with the input 287359614--><ScRiPt%20>alert(1234)</ScRiPt><!-- leads to cross site scripting. It is… | |
| Modificada | Media (6.1) | 0.47% | — | Martmbithi Internet Banking System | 22/10/2023 | 17/6/2026 | A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file pages_transfer_money.php. The manipulation of the argument account_number with the input 357146928--><ScRiPt%20>alert(9206)</ScRiPt><!-- leads to cross… | |
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 22/10/2023 | 17/6/2026 | A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file pages_reset_pwd.php. The manipulation of the argument email with the input testing%40example.com'%26%25<ScRiPt%20>alert(9860)</ScRiPt> leads to… | |
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 22/10/2023 | 17/6/2026 | A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been classified as problematic. Affected is an unknown function of the file pages_system_settings.php. The manipulation of the argument sys_name with the input <ScRiPt >alert(991)</ScRiPt> leads to cross site scripting. It is possible to launch… | |
| Modificada | Crítica (9.8) | 0.65% | — | Martmbithi Internet Banking System | 22/10/2023 | 17/6/2026 | A vulnerability was found in CodeAstro Internet Banking System 1.0 and classified as critical. This issue affects some unknown processing of the file pages_reset_pwd.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (5.4) | 0.32% | — | Oracle Banking Trade Finance | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance.… | |
| Modificada | Media (5.4) | 0.32% | — | Oracle Banking Trade Finance | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance.… | |
| Modificada | Media (5.4) | 0.32% | — | Oracle Banking Trade Finance | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance.… | |
| Modificada | Media (5.9) | 0.37% | — | Oracle Banking Trade Finance | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.5-14.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance.… | |
| Modificada | Media (5.4) | 0.34% | — | Oracle Banking Trade Finance | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.5-14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Trade Finance.… | |
| Modificada | Media (5.9) | 0.32% | — | Oracle Flexcube Universal Banking | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5-14.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.5) | 0.31% | — | Oracle Flexcube Universal Banking | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (5.4) | 0.32% | — | Oracle Flexcube Universal Banking | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (4.6) | 0.38% | — | Oracle Banking Payments | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Book/Internal Transfer). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking… | |
| Modificada | Media (6) | 0.43% | — | Oracle Banking Virtual Account Management | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to… | |
| Modificada | Media (6) | 0.43% | — | Oracle Banking Virtual Account Management | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.1) | 0.58% | — | Oracle Banking Virtual Account Management | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: SMS Module). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.1) | 0.55% | — | Oracle Banking Virtual Account Management | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Routing Hub). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (5.3) | 0.40% | — | Oracle Banking Virtual Account Management | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to… | |
| Modificada | Media (5.3) | 0.40% | — | Oracle Banking Virtual Account Management | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Internal Tfr Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to… | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer_action.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/manage_customers.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/customer_transactions.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/transactions.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds_action.php. |