Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.51% | — | IBM DB2IBM DB2 Warehouse | 12/12/2022 | 17/6/2026 | IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237210. | |
| Modificada | Crítica (9.8) | 0.62% | — | House Rental System Project House Rental System | 3/12/2022 | 17/6/2026 | A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-engine.php of the component POST Request Handler. The manipulation of the argument id_photo leads to unrestricted upload. The attack may be launched remotely. The exploit… | |
| Modificada | Crítica (9.8) | 0.67% | — | House Rental System Project House Rental System | 3/12/2022 | 17/6/2026 | A vulnerability has been found in House Rental System and classified as critical. Affected by this vulnerability is an unknown functionality of the file search-property.php of the component POST Request Handler. The manipulation of the argument search_property leads to sql injection. The attack can be launched… | |
| Modificada | Crítica (9.8) | 0.67% | — | House Rental System Project House Rental System | 3/12/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in House Rental System. Affected is an unknown function of the file /view-property.php. The manipulation of the argument property_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.8) | 0.84% | — | Warehouse Management System Project Warehouse Management System | 3/12/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /product/savenewproduct.php?flag=1. The manipulation of the argument upfile leads to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (6.5) | 0.25% | — | IBM DB2 ON Cloud PAK FOR DataIBM DB2 Warehouse ON Cloud PAK FOR DataIBM Db2u | 1/12/2022 | 17/6/2026 | IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212. | |
| Modificada | Alta (7.8) | 0.22% | — | Trendmicro Housecall | 19/9/2022 | 17/6/2026 | A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissive folder om the product installer. | |
| Modificada | Alta (7.5) | 0.95% | — | Oretnom23 Warehouse Management System | 26/7/2022 | 17/6/2026 | Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter. | |
| Modificada | Alta (8.8) | 2.7% | — | Simple House Rental System Project Simple House Rental System | 8/4/2022 | 17/6/2026 | Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (8.8) | 1.7% | — | ClickhouseDebian Linux | 14/3/2022 | 17/6/2026 | Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy<copy_amount>(op, ip, copy_end), don’t exceed the destination buffer’s limits. This issue is… | |
| Modificada | Alta (8.8) | 1.7% | — | ClickhouseDebian Linux | 14/3/2022 | 17/6/2026 | Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy<copy_amount>(op, ip, copy_end), don’t exceed the destination buffer’s limits. | |
| Modificada | Media (6.5) | 1.4% | — | Clickhouse | 14/3/2022 | 17/6/2026 | Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0. | |
| Modificada | Media (6.5) | 1.3% | — | Clickhouse | 14/3/2022 | 17/6/2026 | Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0. | |
| Modificada | Media (6.5) | 1.3% | — | Clickhouse | 14/3/2022 | 17/6/2026 | Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0. | |
| Modificada | Alta (8.1) | 1.6% | — | ClickhouseDebian Linux | 14/3/2022 | 17/6/2026 | Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the lower bounds of… | |
| Modificada | Alta (8.1) | 1.6% | — | ClickhouseDebian Linux | 14/3/2022 | 17/6/2026 | Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of… | |
| Modificada | Media (6.1) | 23% | 💥 Exploit | SAP Knowledge Warehouse | 14/12/2021 | 17/6/2026 | A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensitive data. | |
| Modificada | Media (6.5) | 1.1% | — | Antennahouse Office Server Document Converter | 1/11/2021 | 17/6/2026 | Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition to the other servers by processing a specially crafted XML document. | |
| Modificada | Alta (7.5) | 1.5% | — | Antennahouse Office Server Document Converter | 1/11/2021 | 17/6/2026 | Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by processing a specially crafted XML document. | |
| Modificada | Alta (7) | 0.52% | — | Trendmicro Housecall FOR Home Networks | 29/9/2021 | 17/6/2026 | An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library. Please note that an attacker must first… | |
| Modificada | Media (5.4) | 0.88% | 💥 PoC | House Rental AND Property Listing PHP Project House Rental AND Property Listing PHP | 23/7/2021 | 17/6/2026 | Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number. | |
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modificada | Alta (7.3) | 0.35% | — | Trendmicro Housecall FOR Home Networks | 12/5/2021 | 17/6/2026 | An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please… | |
| Modificada | Alta (7.3) | 0.26% | — | Trendmicro Housecall FOR Home Networks | 12/5/2021 | 17/6/2026 | An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please note that… | |
| Modificada | Media (5.3) | 2.1% | — | Novel Boutique House-plus Project Novel Boutique House-plus | 29/4/2021 | 17/6/2026 | Directory Traversal in the fileDownload function in com/java2nb/common/controller/FileController.java in Novel-plus (小说精品屋-plus) 3.5.1 allows attackers to read arbitrary files via the filePath parameter. |