Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Random Values Vulnerability.
ModificadaCrítica (9.8)1.2%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability.
ModificadaCrítica (9.8)1.1%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, contain an Improper Input Validation Vulnerability.
ModificadaCrítica (9.8)1.2%—Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+211/7/202217/6/2026
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.
ModificadaMedia (4.3)0.57%—Zhyd Oneblog23/6/202217/6/2026
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
ModificadaMedia (6.5)0.58%—Zhyd Oneblog23/6/202217/6/2026
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.
ModificadaMedia (4.3)0.57%—Zhyd Oneblog23/6/202217/6/2026
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
ModificadaMedia (5.4)0.30%—Sideblog Project Sideblog13/6/202217/6/2026
The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping
ModificadaAlta (7.5)1.1%—Dell Bsafe Micro-edition-suiteOracle DatabaseOracle Http ServerOracle Security Service+11/6/202217/6/2026
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability.
ModificadaAlta (7.5)0.69%—Dell Bsafe Micro-edition-suiteOracle Http ServerOracle Security ServiceOracle Weblogic Server Proxy Plug-in1/6/202217/6/2026
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.
ModificadaMedia (6.1)1.7%💥 PoCOwasp Enterprise Security APIOracle Weblogic ServerNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation27/4/202217/6/2026
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a potential for a cross-site scripting vulnerability in ESAPI caused by a incorrect regular expression for "onsiteURL" in the **antisamy-esapi.xml** configuration file that can…
ModificadaCrítica (9.8)2.8%💥 PoCOwasp Enterprise Security APIOracle Weblogic ServerNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation25/4/202217/6/2026
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a child of the specified parent…
ModificadaMedia (6.1)1.3%💥 PoCAntisamy Project AntisamyOracle Enterprise Manager Base PlatformOracle Weblogic Server21/4/202217/6/2026
OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367.
ModificadaMedia (6.1)0.88%—Oracle Weblogic Server19/4/202217/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.…
ModificadaAlta (7.5)1.4%—Oracle Weblogic Server19/4/202217/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3/IIOP to compromise Oracle WebLogic Server.…
ModificadaAlta (7.5)2.1%—Nekohtml Project NekohtmlOracle Weblogic Server11/4/202217/6/2026
org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to upgrade to `>= 1.9.22.noko2`. Note: The upstream library `org.cyberneko.html` is no longer…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+341/4/202217/6/2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to…
ModificadaAlta (7.5)4.9%💥 PoCFasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+3211/3/202217/6/2026
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
ModificadaMedia (6.5)0.67%—Oneblog Project Oneblog25/1/202217/6/2026
OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators beyond their authority.
ModificadaMedia (6.5)12%—Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+2524/1/202225/8/2026
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version…
ModificadaMedia (5.4)0.50%—Oneblog Project Oneblog19/1/202217/6/2026
A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in the background.
ModificadaMedia (6.1)0.95%—Oracle Weblogic Server19/1/202217/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
ModificadaAlta (7.5)93%💥 ExploitOracle Weblogic Server19/1/202217/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (6.1)0.95%—Oracle Weblogic Server19/1/202217/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Sample apps). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful…
ModificadaMedia (6.5)1.2%—Oracle Weblogic Server19/1/202217/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful…