Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.2% | — | Curriculum Evaluation System Project Curriculum Evaluation System | 16/11/2018 | 17/6/2026 | Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb. | |
| Modificada | Media (6.1) | 30% | — | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Alta (8.1) | 1.9% | — | Oracle Financial Services Hedge Management AND Ifrs Valuations | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.1) | 1.1% | — | Oracle Financial Services Hedge Management AND Ifrs Valuations | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (6.2) | 4.9% | — | Apache StrutsNetapp Oncommand BalanceOracle Agile PLM FrameworkOracle Enterprise Manager FOR Virtualization+8 | 1/12/2017 | 17/6/2026 | In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload. | |
| Modificada | Crítica (9.8) | 90% | — | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Media (6.5) | 2.0% | — | Jg786a HP Flexfabric 12500 4-port 100gbe CFP FDJg787a HP Flexfabric 12500 4-port 100gbe CFP FD TAAJg788a HP Flexfabric 12500 4-port 100gbe CFP FGJg789a HP Flexfabric 12500 4-port 100gbe CFP FG TAA+83 | 5/1/2016 | 17/6/2026 | HPE Networking Products, originally branded as Comware 5, Comware 7, H3C, or HP, allow remote attackers to bypass intended access restrictions or cause a denial of service via "Virtual routing and forwarding (VRF) hopping." | |
| Modificada | Media (5) | 12% | — | OpensuseCanonical Ubuntu LinuxDebian LinuxLUA+1 | 4/9/2014 | 17/6/2026 | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments. | |
| Modificada | Media (5) | 1.7% | — | Matthewwild Luaexpat | 21/6/2011 | 16/6/2026 | LuaExpat before 1.2.0 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | |
| Modificada | Media (6.8) | 7.1% | — | Viart CMSViart HelpdeskViart Shop EvaluationViart Shop Free | 13/12/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path parameter. NOTE: some of these details are obtained from third… |