Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.74% | — | Support-project Knowledge | 28/4/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Knowledge versions prior to v1.7.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Baja (3.7) | 1.5% | — | Honeywell Experion Process Knowledge System | 13/2/2017 | 17/6/2026 | An issue was discovered in Honeywell Experion Process Knowledge System (PKS) platform: Experion PKS, Release 3xx and prior, Experion PKS, Release 400, Experion PKS, Release 410, Experion PKS, Release 430, and Experion PKS, Release 431. Experion PKS does not properly validate input. By sending a specially crafted… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Knowledge Management | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Knowledge Management | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Knowledge Management | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Knowledge Management | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Knowledge Management | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge… | |
| Modificada | Alta (8.2) | 1.6% | — | Oracle Knowledge Management | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge… | |
| Modificada | Media (6.5) | 9.7% | — | Oracle Knowledge Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote administrators to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Media (4.7) | 2.0% | — | Oracle Knowledge Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via vectors related to Search. NOTE: the previous information is from the July 2016 CPU. Oracle has not commented on… | |
| Modificada | Media (6.5) | 1.9% | — | Oracle Knowledge | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Knowledge component in Oracle Siebel CRM 8.5.x allows remote attackers to affect confidentiality and integrity via vectors related to Information Manager Console. | |
| Modificada | Media (4.3) | 1.7% | — | Oracle Knowledge | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Knowledge component in Oracle Siebel CRM 8.5.x allows remote authenticated users to affect confidentiality via vectors related to Information Manager Console. | |
| Modificada | Baja (3.5) | 0.78% | — | Intranet Knowledgebase | 26/12/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Owl Intranet Knowledgebase 1.10 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Search field to browse.php or (2) the Title field to prefs.php. | |
| Modificada | Media (5.4) | 0.27% | — | Magzter BBC Knowledge Magazine | 19/10/2014 | 17/6/2026 | The BBC Knowledge Magazine (aka com.magzter.bbcknowledge) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Socialknowledge Forest River Forums | 2/10/2014 | 17/6/2026 | The Forest River Forums (aka com.socialknowledge.forestriverforums) application 3.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Socialknowledge Aquarium Advice | 20/9/2014 | 17/6/2026 | The Aquarium Advice (aka com.socialknowledge.aquariumadvice) application 3.7.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.1% | — | Knowledgetree | 22/4/2014 | 17/6/2026 | SQL injection vulnerability in the get_active_session function in the KTAPI_UserSession class in webservice/clienttools/services/mdownload.php in KnowledgeTree 3.7.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the u parameter, related to the getFileName function. | |
| Modificada | Media (4.3) | 1.0% | — | Knowledgeview Editorial AND Management Application | 24/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the KnowledgeView Editorial and Management application allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Media (6.8) | 2.0% | — | Public Knowledge Project Open Harvester Systems | 23/9/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester Systems 2.3.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files. | |
| Modificada | Media (6.8) | 1.3% | — | Public Knowledge Project Open Journal Systems | 23/9/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files. | |
| Modificada | Media (6.8) | 1.1% | — | Public Knowledge Project Open Conference Systems | 23/9/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Conference Systems 2.3.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload a PHP file. | |
| Modificada | Media (4.3) | 1.8% | — | JAM Warehouse Knowledgetree Open Source | 20/9/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in config/dmsDefaults.php in KnowledgeTree 3.7.0.2 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) login.php, (2) admin.php, or (3) preferences.php. | |
| Modificada | Media (5) | 2.7% | — | Interspire Knowledge Manager | 3/12/2009 | 16/6/2026 | Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.0% | — | Knowledgetree Document Management | 6/1/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-4281. | |
| Modificada | Media (6.5) | 1.1% | — | Knowledgetree Document Management | 6/1/2009 | 16/6/2026 | The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests. |