Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

171 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Vikwp Vikbooking Hotel Booking Engine & Property Management System Plugin19/4/202217/6/2026
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.
ModificadaAlta (7.5)12%—Apache TomcatNetapp HCINetapp Management Services FOR Element SoftwareDebian Linux+1414/10/202117/6/2026
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a…
ModificadaMedia (5.4)0.88%💥 PoCHouse Rental AND Property Listing PHP Project House Rental AND Property Listing PHP23/7/202117/6/2026
Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.
ModificadaMedia (5.3)75%—Apache TomcatApache TomeeDebian LinuxOracle Agile Product Lifecycle Management+1812/7/202125/8/2026
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if…
ModificadaMedia (6.5)9.9%—Apache TomcatOracle Communications Cloud Native Core PolicyOracle Communications Diameter Signaling RouterOracle Communications Pricing Design Center+312/7/202117/6/2026
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
ModificadaAlta (8.8)3.3%—Pivotal Software Spring SecurityVmware Spring SecurityOracle Communications Element ManagerOracle Communications Interactive Session Recorder+423/2/202117/6/2026
Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the…
ModificadaAlta (8.8)1.2%—Changjia Property Management System Project Changjia Property Management System17/2/202117/6/2026
Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions.
ModificadaAlta (7.5)1.8%—Changjia Property Management System Project Changjia Property Management System17/2/202117/6/2026
The CGE page with download function contains a Directory Traversal vulnerability. Attackers can use this loophole to download system files arbitrarily.
ModificadaAlta (7.5)1.5%—Changjia Property Management System Project Changjia Property Management System17/2/202117/6/2026
The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege.
ModificadaMedia (6.5)1.5%—Oracle Hospitality Opera 5 Property Services21/10/202017/6/2026
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Logging). Supported versions that are affected are 5.5 and 5.6. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5…
ModificadaMedia (6.8)1.4%—Oracle Hospitality Opera 5 Property Services21/10/202017/6/2026
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Logging). Supported versions that are affected are 5.5 and 5.6. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5…
ModificadaCrítica (9.8)2.9%—Projectworlds House Rental AND Property Listing Project27/8/202017/6/2026
File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.
ModificadaCrítica (9.8)3.4%—Property-expr Project Property-expr18/8/202017/6/2026
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModificadaAlta (8.8)0.82%—Realestateconnected Easy Property Listings18/2/202017/6/2026
Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaMedia (5.7)1.2%—Oracle Hospitality Opera Property Management15/1/202017/6/2026
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Login). Supported versions that are affected are 5.5 and 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. Successful attacks…
ModificadaMedia (6.1)1.0%—Oracle Hospitality Opera Property Management15/1/202017/6/2026
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Printing). The supported version that is affected is 5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. Successful attacks…
ModificadaAlta (7.1)1.1%—Oracle Hospitality Opera Property Management15/1/202017/6/2026
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Login). The supported version that is affected is 5.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. Successful attacks of this…
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaMedia (6.1)1.00%—Realestateconnected Easy Property Listings30/8/201917/6/2026
The easy-property-listings plugin before 3.4 for WordPress has XSS.
ModificadaMedia (6.5)1.4%—Property Rental Software Project Property Rental Software21/3/201917/6/2026
PHP Scripts Mall Property Rental Software 2.1.4 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2016/08 directory.
ModificadaAlta (7.6)0.91%—Oracle Hospitality Cruise Shipboard Property Management System16/1/201917/6/2026
Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS Suite). The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle…
ModificadaMedia (5.1)0.42%—Oracle Hospitality Cruise Shipboard Property Management System16/1/201917/6/2026
Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: DGS RES Online, FMS Sender, FMS Receiver, OHC WPF Security). The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker…
ModificadaMedia (6.7)0.37%—Oracle Hospitality Cruise Shipboard Property Management System16/1/201917/6/2026
Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS Suite). The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle…
ModificadaMedia (5.5)0.44%—Oracle Hospitality Cruise Shipboard Property Management System17/10/201817/6/2026
Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: OHC ENOAD). The supported version that is affected is 8.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle…
Orbitaley — Vulnerabilidades