Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.35% | — | Stm32cube Middleware | 22/7/2021 | 17/6/2026 | An issue in USBH_ParseCfgDesc() of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service due to the system hanging when trying to set a remote wake-up feature. | |
| Modificada | Media (6.8) | 0.47% | — | Stm32cube Middleware | 22/7/2021 | 17/6/2026 | A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code. | |
| Modificada | Media (6.8) | 0.47% | — | Stm32cube Middleware | 22/7/2021 | 17/6/2026 | A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modificada | Media (4.6) | 0.50% | — | Oracle Flexcube Universal Banking | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Loans And Deposits). Supported versions that are affected are 12.0-12.4, 14.0-14.4 and . Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (5.9) | 1.3% | — | Oracle Flexcube Universal Banking | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Flex-Branch). Supported versions that are affected are 12.3, 12.4, 14.0-14.4 and . Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (7.5) | 13% | — | Apache Commons CompressOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Enterprise Default Management+30 | 13/7/2021 | 17/6/2026 | When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package. | |
| Modificada | Alta (7.5) | 11% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Apis+23 | 13/7/2021 | 17/6/2026 | When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package. | |
| Modificada | Alta (7.5) | 12% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+20 | 13/7/2021 | 17/6/2026 | When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package. | |
| Modificada | Alta (7.5) | 12% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+22 | 13/7/2021 | 17/6/2026 | When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package. | |
| Modificada | Media (6.5) | 3.0% | — | Apache SshdOracle Banking PaymentsOracle Banking Trade FinanceOracle Banking Treasury Management+5 | 12/7/2021 | 17/6/2026 | A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0 | |
| Modificada | Alta (7.5) | 2.1% | — | Ec-cube | 1/7/2021 | 17/6/2026 | Improper access control vulnerability in EC-CUBE 4.0.6 (EC-CUBE 4 series) allows a remote attacker to bypass access restriction and obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6.1) | 1.1% | — | Ec-cube | 28/6/2021 | 17/6/2026 | Cross-site scripting vulnerability in EC-CUBE EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation. | |
| Modificada | Media (6.1) | 1.6% | — | Ec-cube | 28/6/2021 | 17/6/2026 | Cross-site scripting vulnerability in EC-CUBE EC-CUBE 3.0.0 to 3.0.18-p2 (EC-CUBE 3 series) and EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation. | |
| Modificada | Media (5.4) | 0.81% | — | Roundcube Webmail | 24/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php. | |
| Modificada | Media (5.4) | 0.92% | — | Roundcube Webmail | 24/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php. | |
| Modificada | Media (6.1) | 0.75% | — | Ec-cube Business Form Output | 22/6/2021 | 17/6/2026 | Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation. | |
| Modificada | Media (6.1) | 0.75% | — | Ec-cube Email Newsletters Management | 22/6/2021 | 17/6/2026 | Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation. | |
| Modificada | Media (6.1) | 0.76% | — | Ec-cube Business Form Output | 22/6/2021 | 17/6/2026 | Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecified vector. | |
| Modificada | Media (6.1) | 1.1% | — | Ec-cube Delivery Slip NumberEc-cube Delivery Slip Number CSV Bulk RegistrationEc-cube Delivery Slip Number Mail | 22/6/2021 | 17/6/2026 | Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier, Delivery slip number csv bulk registration plugin (3.0 series) 1.0.8 and earlier, and Delivery slip number mail plugin (3.0 series) 1.0.8 and earlier) allows remote attackers to inject an arbitrary… | |
| Modificada | Media (5.5) | 3.4% | — | Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+8 | 12/6/2021 | 17/6/2026 | In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. | |
| Modificada | Alta (7.2) | 1.2% | — | Cubecoders AMP | 10/6/2021 | 17/6/2026 | An issue was discovered in CubeCoders AMP before 2.1.1.8. A lack of validation of the Java Version setting means that an unintended executable path can be set. The result is that high-privileged users can trigger code execution. | |
| Modificada | Media (5.4) | 0.70% | — | Cubecart | 27/5/2021 | 17/6/2026 | Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, the injected cookie becomes valid, giving the attacker access to the user's… | |
| Modificada | Media (6.1) | 0.33% | — | Stm32cubel4 Firmware | 21/5/2021 | 17/6/2026 | STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control. | |
| Modificada | Alta (7) | 0.34% | — | Stm32cubel4 Firmware | 21/5/2021 | 17/6/2026 | STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase. |