Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.98% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Cf-release | 19/3/2018 | 17/6/2026 | In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerability where a refresh token that would otherwise be insufficient to obtain an… | |
| Modificada | Media (5.4) | 0.83% | — | Oracle Peoplesoft Enterprise Human Capital Management Human Resources | 18/1/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Modificada | Media (6.1) | 1.1% | — | Oracle Peoplesoft Enterprise Human Capital Management Human Resources | 18/1/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources component of Oracle PeopleSoft Products (subcomponent: Company Dir / Org Chart Viewer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft… | |
| Modificada | Alta (7.8) | 0.52% | — | Kcapifony Project Kcapifony | 10/1/2018 | 17/6/2026 | lib/ksymfony1.rb in the kcapifony gem 2.1.6 for Ruby places database user passwords on the (1) mysqldump, (2) pg_dump, (3) mysql, and (4) psql command lines, which allows local users to obtain sensitive information by listing the processes. | |
| Modificada | Media (6.5) | 0.95% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Cf-release | 28/11/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from creating subdomains to an already existing route that belongs to a… | |
| Modificada | Media (4.6) | 1.0% | — | Oracle Peoplesoft Enterprise Human Capital Management Human Resources | 19/10/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM. Successful attacks… | |
| Modificada | Media (5.4) | 1.0% | — | Oracle Peoplesoft Enterprise Human Capital Management Human Resources | 19/10/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM. Successful attacks… | |
| Modificada | Alta (7.8) | 1.2% | — | Cloudfoundry Cf-releasePivotal Capi-release | 4/10/2017 | 17/6/2026 | In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application.… | |
| Modificada | Alta (7.5) | 1.4% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 21/8/2017 | 17/6/2026 | In Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.38.0 and cf-release versions after v244 and prior to v270, there is an incomplete fix for CVE-2017-8035. If you took steps to remediate CVE-2017-8035 you should also upgrade to fix this CVE. A carefully crafted CAPI request from a Space… | |
| Modificada | Alta (7.5) | 1.4% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 25/7/2017 | 17/6/2026 | An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-release versions after v244 and prior to v268. A carefully crafted CAPI request from a Space Developer can allow them to gain access to files on the Cloud Controller VM for… | |
| Modificada | Alta (7.8) | 1.0% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 25/7/2017 | 17/6/2026 | An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions prior to v1.35.0 and cf-release versions prior to v268. A filesystem traversal vulnerability exists in the Cloud Controller that allows a space developer to escalate privileges by pushing a specially crafted… | |
| Modificada | Alta (7.8) | 1.4% | — | Cloudfoundry Capi-release | 24/7/2017 | 17/6/2026 | An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release version 1.33.0 (only). The original fix for CVE-2017-8033 included in CAPI-release 1.33.0 introduces a regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially… | |
| Modificada | Media (6.6) | 0.75% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-releaseCloudfoundry Routing-release | 17/7/2017 | 17/6/2026 | The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to… | |
| Modificada | Media (6.5) | 0.97% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to 1.12.0. A user with the SpaceAuditor role is over-privileged with the ability to restage applications. This could cause application downtime if the restage fails. | |
| Modificada | Media (4.3) | 1.3% | — | Oracle Peoplesoft Enterprise Human Capital Management Eperformance | 27/1/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM ePerformance component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM ePerformance.… | |
| Modificada | Media (6.1) | 0.97% | — | EMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum TaskspaceEMC Documentum Webtop | 23/1/2017 | 17/6/2026 | EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version 6.7SP3, prior to P02; and EMC Documentum Capital Projects Version 1.9, prior to P30 and Version 1.10, prior to P17; and EMC Documentum Administrator Version 7.0, Version 7.1, and Version 7.2 prior to… | |
| Modificada | Alta (7.5) | 1.7% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 13/1/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI-release versions prior to v1.12.0. Cloud Foundry logs the credentials returned from service brokers in Cloud Controller system component logs. These logs are written to disk and often sent to a log aggregator via syslog. | |
| Modificada | Media (4.3) | 1.7% | — | Oracle Peoplesoft Enterprise Human Capital Management Time AND Labor | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality via unknown vectors. | |
| Modificada | Media (4.2) | 1.4% | — | Oracle Peoplesoft Enterprise Human Capital Management Talent Acquisition Manager | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Talent Acquisition Manager. | |
| Modificada | Media (4.8) | 1.00% | — | Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote administrators to affect confidentiality and integrity via vectors related to Candidate Gateway. | |
| Modificada | Media (5.9) | 0.57% | — | Misys Fusioncapital Opics Plus | 19/7/2016 | 17/6/2026 | Misys FusionCapital Opics Plus does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.6% | — | Misys Fusioncapital Opics Plus | 19/7/2016 | 17/6/2026 | Misys FusionCapital Opics Plus allows remote authenticated users to gain privileges via a man-in-the-middle attack that modifies the xmlMessageOut parameter. | |
| Modificada | Media (6.5) | 1.1% | — | Misys Fusioncapital Opics Plus | 19/7/2016 | 17/6/2026 | Multiple SQL injection vulnerabilities in Misys FusionCapital Opics Plus allow remote authenticated users to execute arbitrary SQL commands via the (1) ID or (2) Branch parameter. | |
| Modificada | Media (6.3) | 1.3% | — | EMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum TaskspaceEMC Documentum Webtop | 23/6/2016 | 17/6/2026 | EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated users to bypass intended access restrictions and execute arbitrary… | |
| Modificada | Media (5.4) | 1.0% | — | Oracle Peoplesoft Enterprise Human Capital Management Eperformance | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to ePerformance. |