Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.3% | — | Talend Restlet | 19/2/2020 | 17/6/2026 | The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages. | |
| Modificada | Alta (7.5) | 2.0% | — | Talend Restlet | 18/12/2019 | 16/6/2026 | An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information. | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Peoplesoft Enterprise Human Capital Management Talent Acquisition Manager | 23/4/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager component of Oracle PeopleSoft Products (subcomponent: Job Opening). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Modificada | Media (4.2) | 1.4% | — | Oracle Peoplesoft Enterprise Human Capital Management Talent Acquisition Manager | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Talent Acquisition Manager. | |
| Modificada | Alta (7.5) | 1.5% | — | Datalex Airline Booking Software | 2/10/2015 | 17/6/2026 | Datalex airline booking software before 2015-09-03 allows remote attackers to read or write to arbitrary user data via a modified profileId parameter to (1) ValidateFormAction.do or (2) ProfileConfirmEditAddressAction.do. | |
| Modificada | Media (5.4) | 0.27% | — | Tabtale Enchanted Fashion Crush | 19/10/2014 | 17/6/2026 | The Enchanted Fashion Crush (aka com.tabtale.springcrushbundleint) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Tabtale ABC Song | 30/9/2014 | 17/6/2026 | The ABC Song (aka com.tabtale.abcsingalong) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Labanquepostale Acces Compte | 9/9/2014 | 17/6/2026 | The Acces Compte (aka com.fullsix.android.labanquepostale.accountaccess) application 3.2.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.30% | — | Playscape Bouncy Bill Easter Tales | 9/9/2014 | 17/6/2026 | The Bouncy Bill Easter Tales (aka mominis.Generic_Android.Bouncy_Bill_Easter_Tales) application 1.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Retale - Weekly ADS & Deals | 9/9/2014 | 17/6/2026 | The Retale - Weekly Ads & Deals (aka com.retale.android) application 2.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.00% | — | Labanquepostale | 2/9/2014 | 17/6/2026 | The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | News Defilante Horizontale | 20/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions_newshr.php in the News Defilante Horizontale 4.1.1 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Media (5) | 1.7% | — | Talentsoft Web+ Shop | 20/4/2006 | 16/6/2026 | Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for "Script Not Found" Error is not configured, allows remote attackers to obtain sensitive information via a quote (') or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a "Script Not Found" error… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Talentsoft Web+ Shop | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the deptname parameter, possibly involving the webpshop/ department.wml script. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Totalecommerce | 9/3/2006 | 16/6/2026 | SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it is not clear whether this report is associated with a specific product. If not, then it should not be included in CVE. | |
| Modificada | Alta (7.5) | 1.6% | — | Datalex Bookit Consumer | 4/10/2002 | 16/6/2026 | Datalex PLC BookIt! Consumer before 2.2 stores usernames and passwords in plaintext in a cookie, which could allow remote attackers to gain privileges via Cross-site scripting or sniffing attacks. | |
| Modificada | Alta (10) | 5.9% | — | Talentsoft Web+ Server | 12/8/2002 | 16/6/2026 | Buffer overflow in Talentsoft Web+ 5.0 allows remote attackers to execute arbitrary code via an HTTP request with a long cookie. | |
| Modificada | Alta (10) | 5.3% | — | Talentsoft Web+ Server | 26/7/2002 | 16/6/2026 | Buffer overflow in Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long Web Markup Language (wml) file name to (1) webplus.dll or (2) webplus.exe. | |
| Modificada | Alta (10) | 9.0% | — | Talentsoft Web+ Server | 26/7/2002 | 16/6/2026 | Buffer overflow in webpsvc.exe for Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long argument to webplus.exe program, which triggers the overflow in webpsvc.exe. | |
| Modificada | Alta (7.5) | 7.4% | 💥 Exploit | Lucent VitalanalysisLucent VitaleventLucent VitalhelpLucent Vitalnet+1 | 29/5/2002 | 16/6/2026 | Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user. | |
| Modificada | Media (5) | 7.8% | 💥 Exploit | Talentsoft Web+ | 12/4/2000 | 16/6/2026 | TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program. |