Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.55% | — | Samsung Account | 7/6/2022 | 17/6/2026 | Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission. | |
| Modificada | Media (5.3) | 0.55% | — | Samsung Account | 7/6/2022 | 17/6/2026 | Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission. | |
| Modificada | Alta (7.5) | 0.62% | — | Samsung Account | 7/6/2022 | 17/6/2026 | Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onActivityResult. | |
| Modificada | Media (4.8) | 1.1% | — | Ldap-account-manager Ldap Account ManagerDebian Linux | 15/4/2022 | 17/6/2026 | LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks. An authenticated user can store XSS payloads in the… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+24 | 1/4/2022 | 17/6/2026 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. | |
| Modificada | Media (5.5) | 0.22% | — | Samasung Account | 10/3/2022 | 17/6/2026 | Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in. | |
| Modificada | Media (5.4) | 0.55% | — | Accounting Journal Management Project Accounting Journal Management | 24/2/2022 | 17/6/2026 | Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of the network. | |
| Modificada | Media (6.5) | 0.48% | — | Scratch-wiki Scratch Confirmaccount V3 | 15/2/2022 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account request requirement bypasses. | |
| Modificada | Alta (7.8) | 0.37% | — | Canonical AccountsserviceCanonical Ubuntu Linux | 17/11/2021 | 17/6/2026 | Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus function. This is fixed in versions… | |
| Modificada | Media (4.3) | 0.90% | — | Aifu Cashier Accounting Management System | 16/11/2021 | 17/6/2026 | The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL parameters. | |
| Modificada | Media (5.4) | 0.48% | — | SAP ERP Financial Accounting | 14/9/2021 | 17/6/2026 | SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users. These… | |
| Modificada | Media (6.1) | 0.71% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 11/8/2021 | 17/6/2026 | UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by social engineering leading to take over of victims’ accounts in certain cases along with redirection of UAA users to a malicious sites. | |
| Modificada | Media (5.4) | 0.60% | — | Otrs Time Accounting | 26/7/2021 | 17/6/2026 | In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions prior to 7.0.19. | |
| Modificada | Alta (7.5) | 0.99% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 22/7/2021 | 17/6/2026 | In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server. | |
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modificada | Baja (3.3) | 0.23% | — | Samsung Account | 11/6/2021 | 17/6/2026 | Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component. | |
| Modificada | Alta (8.1) | 0.93% | — | Oracle Subledger Accounting | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Inquiries). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Subledger Accounting. Successful attacks… | |
| Modificada | Alta (7.8) | 0.21% | — | Samsung Account | 9/4/2021 | 17/6/2026 | Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent. | |
| Modificada | Baja (2.4) | 0.29% | — | Samsung Account | 25/3/2021 | 17/6/2026 | Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password. | |
| Modificada | Baja (3.9) | 0.24% | — | Samsung Account | 25/3/2021 | 17/6/2026 | Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log. | |
| Analizada | Crítica (9.1) | 82% | 💥 Exploit | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to… | |
| Analizada | Crítica (9.8) | 15% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security… | |
| Analizada | Alta (8.6) | 47% | 💥 PoC | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+13 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed… | |
| Analizada | Alta (7.5) | 14% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security… | |
| Analizada | Crítica (9.8) | 14% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… |