Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.2) | 0.51% | — | Oracle Hospitality Cruise Fleet Management | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management System component of Oracle Hospitality Applications (subcomponent: Fleet Management System Suite). The supported version that is affected is 9.x. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where… | |
| Modificada | Alta (7.1) | 0.50% | — | Oracle Hospitality Cruise Fleet Management | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management System component of Oracle Hospitality Applications (subcomponent: Fleet Management System Suite). The supported version that is affected is 9.x. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where… | |
| Modificada | Alta (8.1) | 2.0% | — | Oracle Hospitality Cruise Fleet Management | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management System component of Oracle Hospitality Applications (subcomponent: Gangway Activity Web App). The supported version that is affected is 9.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (7.3) | 1.2% | — | Oracle Hospitality Cruise Fleet Management | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management System component of Oracle Hospitality Applications (subcomponent: Fleet Management System Suite). The supported version that is affected is 9.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Media (6.1) | 30% | 💥 PoC | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Alta (7.6) | 0.83% | — | Oracle Hospitality Cruise Fleet Management | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: Emergency Response System). The supported version that is affected is 9.0.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (7.5) | 1.5% | — | Oracle Hospitality Cruise Fleet Management | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: Emergency Response System). The supported version that is affected is 9.0.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Crítica (9.1) | 1.5% | — | Oracle Hospitality Cruise Fleet Management | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: Emergency Response System). The supported version that is affected is 9.0.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Baja (3.1) | 0.87% | — | Oracle Hospitality Cruise Fleet Management | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: GangwayActivityWebApp). The supported version that is affected is 9.0.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (8.4) | 0.38% | — | Oracle Hospitality Cruise Fleet Management | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: BaseMasterPage). The supported version that is affected is 9.0.2.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality… | |
| Modificada | Media (6.1) | 0.94% | — | Oracle Hospitality Cruise Fleet Management | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: BaseMasterPage). The supported version that is affected is 9.0.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality… | |
| Modificada | Media (5.4) | 0.77% | — | Oracle Hospitality Cruise Fleet Management | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: GangwayActivityWebApp). The supported version that is affected is 9.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (7.1) | 1.6% | — | Oracle Hospitality Cruise Fleet Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: Fleet Management System Suite). The supported version that is affected is 9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.1) | 23% | — | Jqueryui Jquery UIOracle Application ExpressOracle Business IntelligenceOracle Hospitality Cruise Fleet Management+9 | 15/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function. | |
| Modificada | Alta (7.8) | 1.9% | — | Cobham Aviator 200Cobham Aviator 300Cobham Aviator 350Cobham Aviator 700d+5 | 15/8/2014 | 17/6/2026 | Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly restrict password recovery, which allows attackers to obtain administrative privileges by leveraging physical access or terminal access to spoof a reset code. | |
| Modificada | Media (5) | 1.7% | — | Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk | 18/11/2012 | 16/6/2026 | Agile FleetCommander and FleetCommander Kiosk before 4.08 store database credentials in cleartext, which allows remote attackers to obtain sensitive information via requests to unspecified pages. | |
| Modificada | Media (5) | 1.2% | — | Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk | 18/11/2012 | 16/6/2026 | Agile FleetCommander and FleetCommander Kiosk before 4.08 use an XOR format for password encryption, which makes it easier for context-dependent attackers to obtain sensitive information by reading a key file and the encrypted strings. | |
| Modificada | Alta (7.5) | 1.9% | — | Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk | 18/11/2012 | 16/6/2026 | Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection" issue. | |
| Modificada | Alta (10) | 3.8% | — | Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk | 18/11/2012 | 16/6/2026 | Multiple unrestricted file upload vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary code by uploading a file via an unspecified page. | |
| Modificada | Media (6.8) | 0.73% | — | Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk | 18/11/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to hijack the authentication of arbitrary users for requests that modify (1) passwords, (2) accounts, or (3) permissions. | |
| Modificada | Media (4.3) | 1.0% | — | Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk | 18/11/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to inject arbitrary web script or HTML via an arbitrary text field. | |
| Modificada | Alta (7.5) | 1.2% | — | Agilefleet FleetcommanderAgilefleet Fleetcommander Kiosk | 18/11/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. |