Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
301 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.80% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 14/2/2022 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (6.1) | 0.81% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 24/1/2022 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Alta (7.5) | 1.6% | — | Soketi Project Soketi | 10/1/2022 | 17/6/2026 | soketi is an open-source WebSockets server. There is an unhandled case when reading POST requests which results in the server crashing if it could not read the body of a request. In the event that a POST request is sent to any endpoint of the server with an empty body, even unauthenticated with the Pusher Protocol, it… | |
| Modificada | Crítica (9.9) | 4.6% | — | Eclipse Keti | 9/9/2021 | 17/6/2026 | Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a sandbox escape vulnerability may lead to post-authentication Remote Code execution. This vulnerability is known to exist in the latest commit at the time of writing this CVE (commit a1c8dbe). For… | |
| Modificada | Crítica (9.9) | 0.95% | — | Eclipse Keti | 9/9/2021 | 17/6/2026 | Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which will escape the configured Groovy sandbox. This vulnerability is known to exist in the latest… | |
| Modificada | Crítica (9.8) | 1.3% | — | Theme Park Ticketing System Project Theme Park Ticketing System | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester Theme Park Ticketing System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_user.php . | |
| Modificada | Alta (8.2) | 1.1% | — | Oracle Marketing | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.… | |
| Modificada | Crítica (9.1) | 1.4% | — | Oracle Marketing | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.… | |
| Modificada | Media (6.1) | 0.93% | — | Oracle Siebel Marketing | 21/7/2021 | 17/6/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing Stand-Alone). Supported versions that are affected are 21.5 and Prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful… | |
| Modificada | Alta (8.8) | 1.3% | — | Wp-buy Conditional Marketing Mailer | 14/5/2021 | 17/6/2026 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps… | |
| Modificada | Crítica (9.1) | 1.3% | — | Oracle Marketing | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.2.7-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Marketing | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Marketing | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Marketing | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.… | |
| Modificada | Media (5.5) | 0.42% | — | Heketi Project HeketiRedhat Gluster StorageRedhat Openshift Container PlatformRedhat Enterprise Linux | 24/11/2020 | 17/6/2026 | An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords. | |
| Modificada | Crítica (9.1) | 2.2% | — | Oracle Marketing | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Marketing | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Marketing | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1 - 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Marketing | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Marketing | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Marketing | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.… | |
| Modificada | Alta (8.1) | 0.95% | — | SAP Marketing | 9/9/2020 | 17/6/2026 | SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of payload is required for an attacker to exploit the vulnerability and perform tasks related to contact and interaction data which impacts Confidentiality and Integrity of… | |
| Modificada | Alta (8.1) | 0.42% | — | IBM Marketing Operations | 20/7/2020 | 17/6/2026 | Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information. | |
| Modificada | Media (5.4) | 0.52% | — | Hcltech Marketing Campaign | 17/7/2020 | 17/6/2026 | "HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. " | |
| Modificada | Media (5.4) | 0.54% | — | Hcltech Marketing Campaign | 17/7/2020 | 17/6/2026 | "HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field." |