Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)11%💥 PoCVmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRMOracle Communications Design Studio+3419/9/202017/6/2026
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
ModificadaMedia (6.3)1.8%—Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+4614/5/202017/6/2026
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an…
ModificadaBaja (3.7)8.1%💥 PoCApache Log4jOracle Communications Application Session ControllerOracle Communications Billing AND Revenue ManagementOracle Communications Eagle FTP Table Base Retrieval+4227/4/202017/6/2026
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
ModificadaAlta (7.5)89%💥 PoCVmware Spring FrameworkOracle Application Testing SuiteOracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Policy+2917/1/202017/6/2026
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaMedia (6.1)2.5%—Eclipse MojarraOracle Mojarra Javaserver FacesOracle Application Testing SuiteOracle Banking Enterprise Product Manufacturing+192/10/201917/6/2026
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
ModificadaMedia (6.1)1.3%—Webcraftic Simple 301 Redirects-addon-bulk Uploader29/8/201917/6/2026
The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.
ModificadaMedia (5.4)1.0%—Mq-woocommerce-products-price-bulk-edit Project Mq-woocommerce-products-price-bulk-edit9/8/201917/6/2026
The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.
ModificadaMedia (6.1)1.1%—Oracle Retail Bulk Data Integration18/7/201817/6/2026
Vulnerability in the Oracle Retail Bulk Data Integration component of Oracle Retail Applications (subcomponent: BDI Job Scheduler). The supported version that is affected is 16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Bulk Data…
ModificadaMedia (4.9)1.6%—Views Bulk Operations Project Views Bulk Operations18/8/201517/6/2026
The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.
ModificadaMedia (4.3)1.2%—Entitybulkdelete Project Entitybulkdelete15/6/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in unspecified administration pages in the EntityBulkDelete module 7.x-1.0 for Drupal allow remote attackers to inject arbitrary web script or HTML via unknown vectors involving creating or editing (1) comments, (2) taxonomy terms, or (3) nodes.
ModificadaMedia (4.9)1.1%—Karim Ratib Views Bulk Operations7/10/201216/6/2026
Unspecified vulnerability in the Views Bulk Operations module 6 before 6.x-1.10 for Drupal allows remote authenticated users with user management permissions to bypass intended access restrictions and delete anonymous users (user 0) via unspecified vectors.
ModificadaMedia (6.8)0.64%—Miura Ubercart Bulk Stock Updater17/9/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors related to formAPI.
ModificadaAlta (7.5)2.2%—Karim Ratib Views Bulk Operations27/6/200916/6/2026
Unspecified vulnerability in Views Bulk Operations 5.x-1.x before 5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupal, allows remote attackers to bypass intended access restrictions and modify "nodes or classes of nodes" via unknown vectors, probably related to registered procedures (aka actions).
ModificadaMedia (4.3)1.1%—Drupal Views Bulk Operations13/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in the theme_views_bulk_operations_confirmation function in views_bulk_operations.module in Views Bulk Operations 5.x before 5.x-1.3 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to…
Orbitaley — Vulnerabilidades