Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.90% | 💥 PoC | Apache Commons Compress | 19/2/2024 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue. | |
| Modificada | Media (5.5) | 0.44% | — | Apache Commons Compress | 19/2/2024 | 17/6/2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue. | |
| Analizada | Media (5.4) | 0.31% | — | Oracle Common Applications | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications.… | |
| Modificada | Crítica (9.8) | 1.5% | — | Github Cmark-gfmGjtorikian Commonmarker | 4/1/2024 | 14/7/2026 | CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more… | |
| Modificada | Alta (7.6) | 0.79% | — | Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+4 | 14/12/2023 | 17/6/2026 | Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit f57bd745b4cbed577ea654fad4701bea4d38b44c. A malicious game streaming server could exploit a buffer overflow vulnerability to crash a moonlight client.… | |
| Modificada | Alta (8.8) | 1.7% | — | Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+3 | 14/12/2023 | 17/6/2026 | Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server… | |
| Modificada | Alta (8.8) | 1.7% | — | Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+3 | 14/12/2023 | 17/6/2026 | Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server… | |
| Modificada | Crítica (9.8) | 0.51% | — | Common-services Soliberte | 14/12/2023 | 17/6/2026 | SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters. | |
| Modificada | Alta (7.5) | 0.76% | — | Common-services Sonice Retour | 17/11/2023 | 17/6/2026 | In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a… | |
| Modificada | Alta (7.5) | 0.58% | — | Common-services Sonice Etiquetage | 18/10/2023 | 17/6/2026 | In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can… | |
| Modificada | Media (6.5) | 0.53% | — | Oracle Peoplesoft Enterprise Cost Center Common Application Objects | 17/10/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Events & Notifications). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC… | |
| Modificada | Media (6.5) | 2.8% | — | Microsoft Common Data Model SDK | 10/10/2023 | 17/6/2026 | Microsoft Common Data Model SDK Denial of Service Vulnerability | |
| Modificada | Alta (8.8) | 0.90% | — | Atos Unify Openscape Common Management | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated remote attacker to execute arbitrary code on the operating system by using the Common Management Portal web interface. This is also known as OCMP-6589. | |
| Modificada | Alta (8.8) | 0.71% | — | Atos Unify Openscape Common Management | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system by leveraging the Common Management Portal web interface for Authenticated remote upload and creation of arbitrary files affecting the underlying… | |
| Modificada | Alta (8.8) | 0.81% | — | Atos Unify Openscape Common Management | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system via a Common Management Portal web interface Path traversal vulnerability allowing write access outside the intended folders. This is also known as… | |
| Modificada | Media (6.1) | 0.54% | — | Mozilla Common Voice | 4/10/2023 | 17/6/2026 | Common Voice is the web app for Mozilla Common Voice, a platform for collecting speech donations in order to create public domain datasets for training voice recognition-related tools. Version 1.88.2 is vulnerable to reflected Cross-Site Scripting given that user-controlled data flows to a path expression (path of a… | |
| Modificada | Alta (7.5) | 0.62% | — | Hitachi OPS Center Common Services | 3/10/2023 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Hitachi Ops Center Common Services on Linux allows DoS.This issue affects Hitachi Ops Center Common Services: before 10.9.3-00. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Common Event Enabler | 29/9/2023 | 17/6/2026 | Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged malicious user may potentially exploit this vulnerability to gain elevated privileges. | |
| Modificada | Media (5.5) | 0.60% | — | Apache Commons Compress | 14/9/2023 | 17/6/2026 | Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0. Users are recommended to upgrade to version 1.24.0, which fixes the issue. A third party can create a malformed TAR file by… | |
| Modificada | Crítica (9.8) | 0.88% | — | SAP CommoncryptolibSAP Content ServerSAP Extended Application Services AND RuntimeSAP Hana Database+5 | 12/9/2023 | 17/6/2026 | SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a… | |
| Modificada | Alta (7.5) | 0.75% | — | SAP CommoncryptolibSAP Content ServerSAP Extended Application Services AND RuntimeSAP Hana Database+5 | 12/9/2023 | 17/6/2026 | SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information. | |
| Modificada | Media (6.1) | 0.38% | — | Commoninja Paytm Payment Donation | 14/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paytm Paytm Payment Donation plugin <= 2.2.0 versions. | |
| Modificada | Media (5.4) | 1.0% | 💥 PoC | Xwiki Commons | 29/6/2023 | 17/6/2026 | Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without script right to either create forms that can be used for phishing attacks or also in… | |
| Modificada | Crítica (9.8) | 2.2% | — | Apache Sling Commons Json | 15/5/2023 | 17/6/2026 | Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are encouraged to consider the Apache Sling… | |
| Modificada | Crítica (9) | 1.3% | 💥 PoC | Xwiki Commons | 20/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1 and massively improved in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus cross-site scripting via invalid HTML… |