Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.4% | — | Oracle Peoplesoft Enterprise Human Capital Management Shared Components | 19/4/2018 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Shared Components component of Oracle PeopleSoft Products (subcomponent: Notepad). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared… | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Datacomponents Tsitebuilder | 29/1/2018 | 17/6/2026 | SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php. | |
| Modificada | Crítica (9.8) | 4.5% | — | Icu-project International Components FOR Unicode | 10/12/2017 | 17/6/2026 | The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for UTF-8 to UTF-8 conversion, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified… | |
| Modificada | Alta (8.1) | 11% | 💥 Exploit | Zetacomponents Mail | 15/11/2017 | 17/6/2026 | The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing… | |
| Modificada | Crítica (9.8) | 3.7% | 💥 Exploit | Datacomponents Tpanel | 29/10/2017 | 17/6/2026 | tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php. | |
| Modificada | Crítica (9.8) | 5.1% | — | Icu-project International Components FOR Unicode | 16/10/2017 | 17/6/2026 | Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue. | |
| Modificada | Alta (7) | 0.52% | — | Rockwellautomation Connected Components Workbench | 19/5/2017 | 17/6/2026 | A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CCWDEVESE, and… | |
| Modificada | Crítica (9.8) | 2.4% | — | Google ChromeIcu-project International Components FOR Unicode | 24/4/2017 | 17/6/2026 | The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represented in a 24-bit field, which allows remote attackers to cause a denial of service (memory… | |
| Modificada | Alta (7.5) | 4.4% | — | Icu-project International Components FOR UnicodeDebian Linux | 14/4/2017 | 17/6/2026 | International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_moveIndex32* function. | |
| Modificada | Alta (7.5) | 4.6% | — | Icu-project International Components FOR UnicodeDebian Linux | 14/4/2017 | 17/6/2026 | International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex* function. | |
| Modificada | Crítica (9.8) | 5.6% | — | Icu-project International Components FOR Unicode | 4/1/2017 | 17/6/2026 | Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted uloc_getDisplayName call. | |
| Modificada | Crítica (9.8) | 5.8% | — | Icu-project International Components FOR Unicode | 17/9/2016 | 17/6/2026 | Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long locale string. | |
| Modificada | Crítica (9.8) | 5.0% | — | Icu-project International Components FOR Unicode | 25/7/2016 | 17/6/2026 | The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have… | |
| Modificada | Media (4.7) | 1.9% | — | Oracle Siebel Core-common Components | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Siebel Core - Common Components component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect integrity via vectors related to iHelp. | |
| Modificada | Media (4.4) | 0.31% | — | Oracle Siebel Core-common Components | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Siebel Core - Common Components component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows local users to affect confidentiality and integrity via vectors related to Email. | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | IBM Sterling B2B IntegratorIBM Sterling IntegratorIBM Tivoli Common ReportingIBM Watson Content Analytics+3 | 2/1/2016 | 17/6/2026 | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library. | |
| Modificada | Alta (10) | 3.0% | — | Apple MAC OS XApple WatchosIcu-project International Components FOR Unicode | 9/10/2015 | 17/6/2026 | Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 24% | 💥 Exploit | Apple MAC OS XApple WatchosIcu-project International Components FOR Unicode | 25/5/2015 | 17/6/2026 | The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 uses an integer data type that is inconsistent with a header file, which allows remote attackers to cause a denial of service (incorrect malloc… | |
| Modificada | Alta (7.5) | 25% | 💥 Exploit | Apple ItunesApple Iphone OSApple MAC OS XApple Watchos+1 | 25/5/2015 | 17/6/2026 | The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (heap-based buffer… | |
| Modificada | Alta (7.5) | 2.1% | — | Google ChromeIcu-project International Components FOR Unicode | 22/1/2015 | 17/6/2026 | The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN revision 293126, as used in Google Chrome before 40.0.2214.91, does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact… | |
| Modificada | Alta (7.5) | 2.2% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+5 | 22/1/2015 | 17/6/2026 | The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier. | |
| Modificada | Alta (7.5) | 2.2% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+5 | 22/1/2015 | 17/6/2026 | The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a look-behind expression. | |
| Modificada | Alta (7.5) | 11% | — | Rockwellautomation Connected Components Workbench | 14/11/2014 | 17/6/2026 | Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an invalid property value to an ActiveX control that was built with an outdated compiler. | |
| Modificada | Media (4.3) | 11% | — | Microsoft Office WEB Apps ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint ServerMicrosoft Sharepoint Server Client Components SDK | 14/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka… | |
| Modificada | Alta (9) | 14% | — | Microsoft Office WEB Apps ServerMicrosoft Project ServerMicrosoft Sharepoint DesignerMicrosoft Sharepoint Foundation+4 | 14/5/2014 | 17/6/2026 | Microsoft Windows SharePoint Services 3.0 SP3; SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1; SharePoint Foundation 2010 SP1 and SP2 and 2013 Gold and SP1; Project Server 2010 SP1 and SP2 and 2013 Gold and SP1; Web Applications 2010 SP1 and SP2; Office Web Apps Server 2013 Gold and SP1;… |