cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-21014,https://securityvulnerability.io/vulnerability/CVE-2024-21014,Unauthenticated Network Access Vulnerability in Oracle Hospitality Simphony by Oracle,"A security vulnerability exists in Oracle Hospitality Simphony, specifically within the Simphony Enterprise Server component, impacting versions 19.1.0 to 19.5.4. This vulnerability allows an unauthenticated attacker with network access via HTTP to exploit the system, potentially leading to a complete takeover of the Oracle Hospitality Simphony application. Organizations utilizing affected versions must prioritize security measures to mitigate risks associated with this exploitation, which poses threats to confidentiality, integrity, and availability.",Oracle,Hospitality Simphony,9.8,CRITICAL,0.0004299999854993075,false,false,false,false,,false,false,2024-04-16T22:15:00.000Z,0 CVE-2024-21010,https://securityvulnerability.io/vulnerability/CVE-2024-21010,Vulnerability in Oracle Hospitality Simphony Product by Oracle,"A vulnerability exists in the Oracle Hospitality Simphony product line, specifically within the Simphony Enterprise Server component. This security flaw affects supported versions from 19.1.0 to 19.5.4 and allows attackers with low privileges and network access via HTTP to exploit the system. While primarily impacting Oracle Hospitality Simphony, the reach of these attacks could extend to additional products, altering the potential consequences of an exploit. Successful exploitation could lead to full control over the Oracle Hospitality Simphony system, posing significant risks to the confidentiality, integrity, and availability of the affected environments.",Oracle,Hospitality Simphony,9.9,CRITICAL,0.0004299999854993075,false,false,false,false,,false,false,2024-04-16T22:15:00.000Z,0 CVE-2024-20989,https://securityvulnerability.io/vulnerability/CVE-2024-20989,Unauthenticated Network Vulnerability in Oracle Hospitality Simphony POS by Oracle,"A vulnerability exists in the Oracle Hospitality Simphony product, particularly affecting the Simphony POS component and versions ranging from 19.1.0 to 19.5.4. This vulnerability allows an unauthenticated attacker with network access via HTTP to breach the security of Oracle Hospitality Simphony. If successfully exploited, the vulnerability can lead to unauthorized access to critical data, as well as total accessibility to all data handled by Oracle Hospitality Simphony. Furthermore, it enables unauthorized actions such as updates, inserts, or deletions of certain data, and can result in a limited denial of service, impacting the overall functionality of the product.",Oracle,Hospitality Simphony,7,HIGH,0.0004299999854993075,false,false,false,false,,false,false,2024-04-16T22:15:00.000Z,0 CVE-2024-20997,https://securityvulnerability.io/vulnerability/CVE-2024-20997,Vulnerability in Oracle Hospitality Simphony Enterprise Server,"A vulnerability exists within the Oracle Hospitality Simphony product, specifically in the Simphony Enterprise Server component. This issue affects supported versions from 19.1.0 to 19.5.4 and can be exploited by a low privileged attacker with network access via HTTP. Successful exploitation of this vulnerability enables attackers to compromise the Oracle Hospitality Simphony system significantly, which may impact additional products as the scope of the attack changes. As a result, the vulnerability poses a serious risk of system takeover, affecting confidentiality, integrity, and availability.",Oracle,Hospitality Simphony,9.9,CRITICAL,0.0004299999854993075,false,false,false,false,,false,false,2024-04-16T22:15:00.000Z,0 CVE-2019-2833,https://securityvulnerability.io/vulnerability/CVE-2019-2833,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Food and Beverage Applications. The supported version that is affected is 18.2.1. Easily exploitable vulnerability allows low privileged attacker having Import/Export privilege with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",Oracle,Hospitality Simphony,7.7,HIGH,0.0008900000248104334,false,false,false,false,,false,false,2019-07-23T23:15:00.000Z,0 CVE-2019-2836,https://securityvulnerability.io/vulnerability/CVE-2019-2836,,Vulnerability in the Oracle Hospitality Simphony component of Oracle Food and Beverage Applications. The supported version that is affected is 18.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).,Oracle,Hospitality Simphony,7.5,HIGH,0.0036100000143051147,false,false,false,false,,false,false,2019-07-23T23:15:00.000Z,0 CVE-2019-2403,https://securityvulnerability.io/vulnerability/CVE-2019-2403,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Food and Beverage Applications. The supported version that is affected is 2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Simphony accessible data as well as unauthorized read access to a subset of Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",Oracle,Hospitality Simphony,6.5,MEDIUM,0.0006600000197067857,false,false,false,false,,false,false,2019-01-16T19:00:00.000Z,0 CVE-2019-2402,https://securityvulnerability.io/vulnerability/CVE-2019-2402,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Food and Beverage Applications. The supported version that is affected is 2.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Simphony accessible data as well as unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Simphony. CVSS 3.0 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L).",Oracle,Hospitality Simphony,7.7,HIGH,0.004339999984949827,false,false,false,false,,false,false,2019-01-16T19:00:00.000Z,0 CVE-2018-2978,https://securityvulnerability.io/vulnerability/CVE-2018-2978,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Import/Export). Supported versions that are affected are 2.8, 2.9 and 2.10. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Simphony accessible data as well as unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Simphony. CVSS 3.0 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).",Oracle,Hospitality Simphony,7.1,HIGH,0.0016199999954551458,false,false,false,false,,false,false,2018-07-18T13:00:00.000Z,0 CVE-2018-2847,https://securityvulnerability.io/vulnerability/CVE-2018-2847,,Vulnerability in the Oracle Hospitality Simphony First Edition component of Oracle Hospitality Applications (subcomponent: Operations). Supported versions that are affected are 1.6 and 1.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony First Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony First Edition accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).,Oracle,Hospitality Simphony First Edition,6.5,MEDIUM,0.0005000000237487257,false,false,false,false,,false,false,2018-04-19T02:00:00.000Z,0 CVE-2018-2853,https://securityvulnerability.io/vulnerability/CVE-2018-2853,,"Vulnerability in the Oracle Hospitality Simphony First Edition component of Oracle Hospitality Applications (subcomponent: Operations, Client Application Loader). Supported versions that are affected are 1.6 and 1.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony First Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Simphony First Edition accessible data as well as unauthorized read access to a subset of Oracle Hospitality Simphony First Edition accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",Oracle,Hospitality Simphony First Edition,5.4,MEDIUM,0.0005499999970197678,false,false,false,false,,false,false,2018-04-19T02:00:00.000Z,0 CVE-2018-2848,https://securityvulnerability.io/vulnerability/CVE-2018-2848,,Vulnerability in the Oracle Hospitality Simphony First Edition component of Oracle Hospitality Applications (subcomponent: Client Application Loader). Supported versions that are affected are 1.6 and 1.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony First Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony First Edition accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).,Oracle,Hospitality Simphony First Edition,7.5,HIGH,0.0009699999936856329,false,false,false,false,,false,false,2018-04-19T02:00:00.000Z,0 CVE-2018-2824,https://securityvulnerability.io/vulnerability/CVE-2018-2824,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Enterprise Management Console). Supported versions that are affected are 2.8, 2.9 and 2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",Oracle,Hospitality Simphony,7.7,HIGH,0.0006900000153109431,false,false,false,false,,false,false,2018-04-19T02:00:00.000Z,0 CVE-2018-2829,https://securityvulnerability.io/vulnerability/CVE-2018-2829,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Enterprise Management Console). The supported version that is affected is 2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data as well as unauthorized update, insert or delete access to some of Oracle Hospitality Simphony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Simphony. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",Oracle,Hospitality Simphony,8.6,HIGH,0.0024900001008063555,false,false,false,false,,false,false,2018-04-19T02:00:00.000Z,0 CVE-2018-2833,https://securityvulnerability.io/vulnerability/CVE-2018-2833,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Enterprise Management Console). Supported versions that are affected are 2.7, 2.8, 2.9 and 2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Simphony accessible data as well as unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",Oracle,Hospitality Simphony,8.1,HIGH,0.0005600000149570405,false,false,false,false,,false,false,2018-04-19T02:00:00.000Z,0 CVE-2018-2851,https://securityvulnerability.io/vulnerability/CVE-2018-2851,,"Vulnerability in the Oracle Hospitality Simphony First Edition component of Oracle Hospitality Applications (subcomponent: Enterprise Management Console). Supported versions that are affected are 1.6 and 1.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony First Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Simphony First Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Hospitality Simphony First Edition accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",Oracle,Hospitality Simphony First Edition,8.1,HIGH,0.0005600000149570405,false,false,false,false,,false,false,2018-04-19T02:00:00.000Z,0 CVE-2018-2802,https://securityvulnerability.io/vulnerability/CVE-2018-2802,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Client Application Loader). Supported versions that are affected are 2.8 and 2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Simphony accessible data as well as unauthorized read access to a subset of Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",Oracle,Hospitality Simphony,5.4,MEDIUM,0.0005499999970197678,false,false,false,false,,false,false,2018-04-19T02:00:00.000Z,0 CVE-2018-2636,https://securityvulnerability.io/vulnerability/CVE-2018-2636,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security). Supported versions that are affected are 2.7, 2.8 and 2.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",Oracle,Hospitality Simphony,8.1,HIGH,0.5157399773597717,false,false,false,true,true,false,false,2018-01-18T02:00:00.000Z,0 CVE-2018-2619,https://securityvulnerability.io/vulnerability/CVE-2018-2619,,Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security). The supported version that is affected is 2.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).,Oracle,Hospitality Simphony,6.5,MEDIUM,0.0005000000237487257,false,false,false,false,,false,false,2018-01-18T02:00:00.000Z,0 CVE-2018-2673,https://securityvulnerability.io/vulnerability/CVE-2018-2673,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: POS). Supported versions that are affected are 2.7, 2.8 and 2.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",Oracle,Hospitality Simphony,5.9,MEDIUM,0.0009699999936856329,false,false,false,false,,false,false,2018-01-18T02:00:00.000Z,0 CVE-2018-2683,https://securityvulnerability.io/vulnerability/CVE-2018-2683,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: POS). Supported versions that are affected are 2.7, 2.8 and 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Simphony. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",Oracle,Hospitality Simphony,7.5,HIGH,0.0005600000149570405,false,false,false,false,,false,false,2018-01-18T02:00:00.000Z,0 CVE-2018-2589,https://securityvulnerability.io/vulnerability/CVE-2018-2589,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Enterprise Server). Supported versions that are affected are 2.7, 2.8 and 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",Oracle,Hospitality Simphony,7.5,HIGH,0.0009699999936856329,false,false,false,false,,false,false,2018-01-18T02:00:00.000Z,0 CVE-2018-2608,https://securityvulnerability.io/vulnerability/CVE-2018-2608,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security). The supported version that is affected is 2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",Oracle,Hospitality Simphony,8.6,HIGH,0.0009699999936856329,false,false,false,false,,false,false,2018-01-18T02:00:00.000Z,0 CVE-2018-2672,https://securityvulnerability.io/vulnerability/CVE-2018-2672,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: POS). Supported versions that are affected are 2.7, 2.8 and 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",Oracle,Hospitality Simphony,7.5,HIGH,0.0009699999936856329,false,false,false,false,,false,false,2018-01-18T02:00:00.000Z,0 CVE-2017-10425,https://securityvulnerability.io/vulnerability/CVE-2017-10425,,"Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Service Host). Supported versions that are affected are 2.6, 2.7, 2.8 and 2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Simphony accessible data as well as unauthorized read access to a subset of Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",Oracle,Hospitality Simphony,5.4,MEDIUM,0.000539999979082495,false,false,false,false,,false,false,2017-10-19T17:00:00.000Z,0