Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.51%—IBM DB2IBM DB2 Warehouse12/12/202217/6/2026
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237210.
ModificadaCrítica (9.8)0.62%—House Rental System Project House Rental System3/12/202217/6/2026
A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-engine.php of the component POST Request Handler. The manipulation of the argument id_photo leads to unrestricted upload. The attack may be launched remotely. The exploit…
ModificadaCrítica (9.8)0.67%—House Rental System Project House Rental System3/12/202217/6/2026
A vulnerability has been found in House Rental System and classified as critical. Affected by this vulnerability is an unknown functionality of the file search-property.php of the component POST Request Handler. The manipulation of the argument search_property leads to sql injection. The attack can be launched…
ModificadaCrítica (9.8)0.67%—House Rental System Project House Rental System3/12/202217/6/2026
A vulnerability, which was classified as critical, was found in House Rental System. Affected is an unknown function of the file /view-property.php. The manipulation of the argument property_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be…
ModificadaCrítica (9.8)0.84%—Warehouse Management System Project Warehouse Management System3/12/202217/6/2026
A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /product/savenewproduct.php?flag=1. The manipulation of the argument upfile leads to unrestricted upload. The attack may be launched remotely. The exploit has been…
ModificadaMedia (6.5)0.25%—IBM DB2 ON Cloud PAK FOR DataIBM DB2 Warehouse ON Cloud PAK FOR DataIBM Db2u1/12/202217/6/2026
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212.
ModificadaAlta (7.8)0.22%—Trendmicro Housecall19/9/202217/6/2026
A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissive folder om the product installer.
ModificadaAlta (7.5)0.95%—Oretnom23 Warehouse Management System26/7/202217/6/2026
Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter.
ModificadaAlta (8.8)2.7%—Simple House Rental System Project Simple House Rental System8/4/202217/6/2026
Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (8.8)1.7%—ClickhouseDebian Linux14/3/202217/6/2026
Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy<copy_amount>(op, ip, copy_end), don’t exceed the destination buffer’s limits. This issue is…
ModificadaAlta (8.8)1.7%—ClickhouseDebian Linux14/3/202217/6/2026
Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy<copy_amount>(op, ip, copy_end), don’t exceed the destination buffer’s limits.
ModificadaMedia (6.5)1.4%—Clickhouse14/3/202217/6/2026
Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.
ModificadaMedia (6.5)1.3%—Clickhouse14/3/202217/6/2026
Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.
ModificadaMedia (6.5)1.3%—Clickhouse14/3/202217/6/2026
Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.
ModificadaAlta (8.1)1.6%—ClickhouseDebian Linux14/3/202217/6/2026
Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the lower bounds of…
ModificadaAlta (8.1)1.6%—ClickhouseDebian Linux14/3/202217/6/2026
Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of…
ModificadaMedia (6.1)23%💥 ExploitSAP Knowledge Warehouse14/12/202117/6/2026
A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensitive data.
ModificadaMedia (6.5)1.1%—Antennahouse Office Server Document Converter1/11/202117/6/2026
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition to the other servers by processing a specially crafted XML document.
ModificadaAlta (7.5)1.5%—Antennahouse Office Server Document Converter1/11/202117/6/2026
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by processing a specially crafted XML document.
ModificadaAlta (7)0.52%—Trendmicro Housecall FOR Home Networks29/9/202117/6/2026
An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library. Please note that an attacker must first…
ModificadaMedia (5.4)0.88%💥 PoCHouse Rental AND Property Listing PHP Project House Rental AND Property Listing PHP23/7/202117/6/2026
Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.
ModificadaAlta (7.5)2.4%—Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+10721/7/202125/8/2026
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks…
ModificadaAlta (7.3)0.35%—Trendmicro Housecall FOR Home Networks12/5/202117/6/2026
An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please…
ModificadaAlta (7.3)0.26%—Trendmicro Housecall FOR Home Networks12/5/202117/6/2026
An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please note that…
ModificadaMedia (5.3)2.1%—Novel Boutique House-plus Project Novel Boutique House-plus29/4/202117/6/2026
Directory Traversal in the fileDownload function in com/java2nb/common/controller/FileController.java in Novel-plus (小说精品屋-plus) 3.5.1 allows attackers to read arbitrary files via the filePath parameter.
Orbitaley — Vulnerabilidades