Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
168 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.0% | — | Oracle Banking Corporate LendingOracle Banking PaymentsOracle Flexcube Enterprise Limits AND Collateral ManagementOracle Flexcube Investor Servicing+1 | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Banking Corporate LendingOracle Banking PaymentsOracle Flexcube Enterprise Limits AND Collateral ManagementOracle Flexcube Investor Servicing+1 | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.5) | 1.9% | — | Oracle Banking Corporate LendingOracle Banking PaymentsOracle Flexcube Enterprise Limits AND Collateral ManagementOracle Flexcube Investor Servicing+1 | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Alta (7.1) | 1.6% | — | Oracle Banking Corporate LendingOracle Banking PaymentsOracle Flexcube Enterprise Limits AND Collateral ManagementOracle Flexcube Investor Servicing+1 | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (5.3) | 1.2% | — | Oracle Banking Payments | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.3.0 and 12.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking… | |
| Modificada | Alta (8.8) | 1.7% | — | Oracle Banking Payments | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments.… | |
| Modificada | Alta (8.1) | 1.8% | — | Oracle Banking Payments | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments.… | |
| Modificada | Media (5.8) | 0.64% | — | Commerce Balanced Payments | 21/4/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Commerce Balanced Payments module for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that delete the user's configured bank accounts via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.94% | — | Commerce Balanced Payments Project Commerce Balanced Payments | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Bank Account Listing Page in the Commerce Balanced Payments module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Tiomobilepay TIO Mobilepay - Bill Payments | 22/9/2014 | 17/6/2026 | The TIO MobilePay - Bill Payments (aka com.tionetworks.mobile.android.tioclient) application 1.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Getswish Swish Payments | 11/9/2014 | 17/6/2026 | The Swish payments (aka se.bankgirot.swish) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Paypal Payments PROZen-cart ZEN Cart | 4/11/2012 | 16/6/2026 | The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP… | |
| Modificada | Media (5.8) | 0.57% | — | Paypal Payments Standard | 4/11/2012 | 16/6/2026 | PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to misinterpretation… | |
| Modificada | Media (5.8) | 0.57% | — | Paypal Payments Standard | 4/11/2012 | 16/6/2026 | PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to… | |
| Modificada | Media (5.8) | 5.7% | — | Apache ActivemqApache AxisPaypal Mass PAYPaypal Payments PRO+1 | 4/11/2012 | 16/6/2026 | Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field… | |
| Modificada | Media (5.8) | 0.57% | — | Amazon Flexible Payments Service | 4/11/2012 | 16/6/2026 | Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to… | |
| Modificada | Media (5) | 1.1% | — | Oscommerce Online MerchantPaypal Website Payments Standard Module | 19/9/2012 | 16/6/2026 | The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Paymentsplus Payments Plus | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in the Payments Plus component 2.1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the type parameter to add.html. |