Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.5% | — | Eclipse MojarraOracle Mojarra Javaserver FacesOracle Application Testing SuiteOracle Banking Enterprise Product Manufacturing+19 | 2/10/2019 | 17/6/2026 | faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled. | |
| Modificada | Media (6.5) | 1.4% | — | Usabilitydynamics Wp-invoice | 20/9/2019 | 17/6/2026 | The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation. | |
| Modificada | Media (5.3) | 1.8% | — | Usabilitydynamics Wp-invoice | 20/9/2019 | 17/6/2026 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates. | |
| Modificada | Media (5.3) | 1.8% | — | Usabilitydynamics Wp-invoice | 20/9/2019 | 17/6/2026 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates. | |
| Modificada | Media (5.3) | 1.8% | — | Usabilitydynamics Wp-invoice | 20/9/2019 | 17/6/2026 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates. | |
| Modificada | Media (5.3) | 2.0% | — | Usabilitydynamics Wp-invoice | 20/9/2019 | 17/6/2026 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval. | |
| Modificada | Media (5.3) | 1.8% | — | Usabilitydynamics Wp-invoice | 20/9/2019 | 17/6/2026 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes. | |
| Modificada | Media (6.1) | 0.95% | — | Ithemes Invoices | 28/8/2019 | 17/6/2026 | Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |
| Modificada | Alta (7.3) | 28% | — | Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+56 | 20/8/2019 | 25/8/2026 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | |
| Modificada | Media (6.1) | 0.92% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 12/8/2019 | 17/6/2026 | The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens. | |
| Modificada | Media (5.4) | 0.67% | — | Invoiceplane | 21/3/2019 | 17/6/2026 | InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.php/invoices/view/## URI. NOTE: this is different from CVE-2018-12255. | |
| Modificada | Alta (7.5) | 9.2% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Communications BRM - Elastic Charging EngineOracle Communications Converged Application Server - Service Controller+36 | 18/10/2018 | 25/8/2026 | Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an… | |
| Modificada | Media (5.4) | 0.80% | — | Paypal PHP Invoice SDK | 2/8/2018 | 17/6/2026 | paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution. | |
| Modificada | Media (6.1) | 0.72% | — | Invoiceplane | 3/7/2018 | 17/6/2026 | An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field. | |
| Modificada | Media (6.1) | 1.3% | — | Invoiceplane | 5/3/2018 | 17/6/2026 | An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php. | |
| Modificada | Media (6.1) | 1.0% | — | Invoiceplane | 9/2/2018 | 17/6/2026 | Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later. | |
| Modificada | Media (6.1) | 30% | 💥 PoC | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Media (5.4) | 0.79% | — | Invoiceninja Invoice Ninja | 3/1/2018 | 17/6/2026 | Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code. | |
| Modificada | Media (5.4) | 0.48% | — | Invoiceplane | 17/11/2017 | 17/6/2026 | InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client side script which will be executed in the browser of users if they visit the manipulated site. | |
| Modificada | Alta (8.8) | 1.1% | — | Invoiceplane | 17/11/2017 | 17/6/2026 | InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver. | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+54 | 4/10/2017 | 25/8/2026 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP… | |
| Modificada | Alta (8.8) | 0.72% | — | Simpleinvoices Simple Invoices | 14/5/2017 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of admins for requests that can (1) create new administrator user accounts and take over the entire application, (2) create regular user accounts, or (3) change configuration… | |
| Modificada | Alta (7.6) | 1.5% | — | Oracle Retail Invoice Matching | 24/4/2017 | 17/6/2026 | Vulnerability in the Oracle Retail Invoice Matching component of Oracle Retail Applications (subcomponent: Security). Supported versions that are affected are 12.0 and 13.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Invoice Matching.… | |
| Modificada | Media (6.8) | 0.64% | — | Invoice Project Invoice | 15/6/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allow remote attackers to hijack the authentication of arbitrary users for requests that (1) create, (2) delete, or (3) alter invoices via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.95% | — | Invoice Project Invoice | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "Administer own invoices" permission to inject arbitrary web script or HTML via unspecified vectors involving nodes of the "Invoice" content type. |