Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
–

110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.2%—Curriculum Evaluation System Project Curriculum Evaluation System16/11/201817/6/2026
Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb.
ModificadaMedia (6.1)30%—JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+4318/1/201817/6/2026
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
ModificadaAlta (8.1)1.9%—Oracle Financial Services Hedge Management AND Ifrs Valuations18/1/201817/6/2026
Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
ModificadaMedia (6.1)1.1%—Oracle Financial Services Hedge Management AND Ifrs Valuations18/1/201817/6/2026
Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
ModificadaMedia (6.2)4.9%—Apache StrutsNetapp Oncommand BalanceOracle Agile PLM FrameworkOracle Enterprise Manager FOR Virtualization+81/12/201717/6/2026
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
ModificadaCrítica (9.8)90%—Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+7517/4/201717/6/2026
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
ModificadaMedia (6.5)2.0%—Jg786a HP Flexfabric 12500 4-port 100gbe CFP FDJg787a HP Flexfabric 12500 4-port 100gbe CFP FD TAAJg788a HP Flexfabric 12500 4-port 100gbe CFP FGJg789a HP Flexfabric 12500 4-port 100gbe CFP FG TAA+835/1/201617/6/2026
HPE Networking Products, originally branded as Comware 5, Comware 7, H3C, or HP, allow remote attackers to bypass intended access restrictions or cause a denial of service via "Virtual routing and forwarding (VRF) hopping."
ModificadaMedia (5)12%—OpensuseCanonical Ubuntu LinuxDebian LinuxLUA+14/9/201417/6/2026
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
ModificadaMedia (5)1.7%—Matthewwild Luaexpat21/6/201116/6/2026
LuaExpat before 1.2.0 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
ModificadaMedia (6.8)7.1%—Viart CMSViart HelpdeskViart Shop EvaluationViart Shop Free13/12/200716/6/2026
PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path parameter. NOTE: some of these details are obtained from third…