Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

168 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)1.0%—Oracle Banking Corporate LendingOracle Banking PaymentsOracle Flexcube Enterprise Limits AND Collateral ManagementOracle Flexcube Investor Servicing+119/4/201817/6/2026
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
ModificadaMedia (6.1)1.4%—Oracle Banking Corporate LendingOracle Banking PaymentsOracle Flexcube Enterprise Limits AND Collateral ManagementOracle Flexcube Investor Servicing+119/4/201817/6/2026
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
ModificadaMedia (6.5)1.9%—Oracle Banking Corporate LendingOracle Banking PaymentsOracle Flexcube Enterprise Limits AND Collateral ManagementOracle Flexcube Investor Servicing+119/4/201817/6/2026
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
ModificadaAlta (7.1)1.6%—Oracle Banking Corporate LendingOracle Banking PaymentsOracle Flexcube Enterprise Limits AND Collateral ManagementOracle Flexcube Investor Servicing+119/4/201817/6/2026
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
ModificadaMedia (5.3)1.2%—Oracle Banking Payments18/1/201817/6/2026
Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.3.0 and 12.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking…
ModificadaAlta (8.8)1.7%—Oracle Banking Payments18/1/201817/6/2026
Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments.…
ModificadaAlta (8.1)1.8%—Oracle Banking Payments18/1/201817/6/2026
Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments.…
ModificadaMedia (5.8)0.64%—Commerce Balanced Payments21/4/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Commerce Balanced Payments module for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that delete the user's configured bank accounts via unspecified vectors.
ModificadaBaja (3.5)0.94%—Commerce Balanced Payments Project Commerce Balanced Payments21/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Bank Account Listing Page in the Commerce Balanced Payments module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)0.27%—Tiomobilepay TIO Mobilepay - Bill Payments22/9/201417/6/2026
The TIO MobilePay - Bill Payments (aka com.tionetworks.mobile.android.tioclient) application 1.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Getswish Swish Payments11/9/201417/6/2026
The Swish payments (aka se.bankgirot.swish) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.8)0.57%—Paypal Payments PROZen-cart ZEN Cart4/11/201216/6/2026
The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP…
ModificadaMedia (5.8)0.57%—Paypal Payments Standard4/11/201216/6/2026
PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to misinterpretation…
ModificadaMedia (5.8)0.57%—Paypal Payments Standard4/11/201216/6/2026
PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to…
ModificadaMedia (5.8)5.7%—Apache ActivemqApache AxisPaypal Mass PAYPaypal Payments PRO+14/11/201216/6/2026
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field…
ModificadaMedia (5.8)0.57%—Amazon Flexible Payments Service4/11/201216/6/2026
Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to…
ModificadaMedia (5)1.1%—Oscommerce Online MerchantPaypal Website Payments Standard Module19/9/201216/6/2026
The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.
ModificadaAlta (7.5)1.0%💥 ExploitPaymentsplus Payments Plus1/11/201116/6/2026
SQL injection vulnerability in the Payments Plus component 2.1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the type parameter to add.html.
Orbitaley — Vulnerabilidades