Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.1% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 18/7/2018 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Construction and Engineering Suite (subcomponent: Web Access). Supported versions that are affected are 8.4, 15.x, 16.x and 17.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP… | |
| Modificada | Media (6.1) | 1.1% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 18/7/2018 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Construction and Engineering Suite (subcomponent: Web Access). Supported versions that are affected are 8.4, 15.x, 16.x and 17.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP… | |
| Modificada | Media (5.9) | 2.7% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Diameter Signaling Router+29 | 25/6/2018 | 25/8/2026 | Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a… | |
| Modificada | Alta (8.8) | 1.1% | — | Portfoliocms Project Portfoliocms | 13/6/2018 | 17/6/2026 | portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI. | |
| Modificada | Alta (7.2) | 1.1% | — | Portfoliocms Project Portfoliocms | 11/6/2018 | 17/6/2026 | portfolioCMS 1.0.5 has SQL Injection via the admin/portfolio.php preview parameter. | |
| Modificada | Alta (7.7) | 1.3% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 19/4/2018 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Construction and Engineering Suite (subcomponent: Web Access). Supported versions that are affected are 16.2 and 17.1 - 17.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Crítica (9.8) | 1.2% | — | Microfocus Project AND Portfolio Management Center | 22/2/2018 | 17/6/2026 | XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to allow XML External Entity (XXE) | |
| Modificada | Media (5.4) | 0.78% | — | Microfocus Project AND Portfolio Management | 15/2/2018 | 17/6/2026 | A Remote Cross-Site Scripting vulnerability in HPE Project and Portfolio Management (PPM) version v9.30, v9.31, v9.32, v9.40 was found. | |
| Modificada | Media (6.1) | 0.68% | — | Extensis Portfolio Netpublish | 1/1/2018 | 17/6/2026 | netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447. | |
| Modificada | Media (4.3) | 0.71% | — | Techno - Portfolio Management Panel Project Techno - Portfolio Management Panel | 15/12/2017 | 17/6/2026 | Techno - Portfolio Management Panel through 2017-11-16 allows full path disclosure via an invalid s parameter to panel/search.php. | |
| Modificada | Alta (8.8) | 0.96% | — | Techno - Portfolio Management Panel Project Techno - Portfolio Management Panel | 15/12/2017 | 17/6/2026 | Techno - Portfolio Management Panel through 2017-11-16 allows SQL Injection via the panel/search.php s parameter. | |
| Modificada | Media (5.4) | 0.51% | — | Techno - Portfolio Management Panel Project Techno - Portfolio Management Panel | 15/12/2017 | 17/6/2026 | Techno - Portfolio Management Panel through 2017-11-16 allows XSS via the panel/search.php s parameter. | |
| Modificada | Media (4.3) | 0.55% | — | Techno - Portfolio Management Panel Project Techno - Portfolio Management Panel | 15/12/2017 | 17/6/2026 | Techno - Portfolio Management Panel through 2017-11-16 does not check authorization for panel/portfolio.php?action=delete requests that remove feedback. | |
| Modificada | Alta (7.3) | 0.50% | — | Microfocus Project AND Portfolio Management | 13/12/2017 | 17/6/2026 | Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow a Cross-Site Forgery attack. | |
| Modificada | Alta (7.4) | 1.0% | — | Microfocus Project AND Portfolio Management | 13/12/2017 | 17/6/2026 | Man-In-The-Middle vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow a Man-in-the-middle attack. | |
| Modificada | Crítica (9.8) | 8.6% | 💥 Exploit | Techno - Portfolio Management Panel Project Techno - Portfolio Management Panel | 11/12/2017 | 17/6/2026 | Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request. | |
| Modificada | Media (4.3) | 1.4% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP… | |
| Modificada | Media (6.5) | 1.0% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP… | |
| Modificada | Media (5.4) | 3.9% | 💥 Exploit | Oracle Primavera P6 Enterprise Project Portfolio Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and 16.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.5) | 1.9% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 8/8/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Alta (8.1) | 2.1% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 24/4/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 24/4/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Crítica (9.9) | 2.1% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 24/4/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access (Apache Commons BeanUtils)). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerability allows low privileged attacker… | |
| Modificada | Crítica (10) | 2.0% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 27/1/2017 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.2, 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via… |