Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

53 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+341/4/202217/6/2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+241/4/202217/6/2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
ModificadaAlta (7.5)7.9%—JenkinsXstreamFedoraproject FedoraDebian Linux+71/2/202217/6/2026
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input…
ModificadaCrítica (9.8)30%—Linuxfoundation DojoOracle Communications Policy ManagementOracle Primavera UnifierOracle Weblogic Server+117/12/202117/6/2026
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
ModificadaCrítica (9.8)18%—Mozilla NSSMozilla NSS ESRNetapp Cloud BackupNetapp E-series Santricity OS Controller+68/12/202117/6/2026
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate…
ModificadaMedia (5.3)75%—Apache TomcatApache TomeeDebian LinuxOracle Agile Product Lifecycle Management+1812/7/202125/8/2026
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if…
ModificadaMedia (4.8)9.9%💥 PoCApache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+5613/4/202125/8/2026
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling…
ModificadaMedia (5.9)64%💥 PoCOpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+10225/3/202117/6/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
AnalizadaCrítica (9.1)82%💥 ExploitNetapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to…
AnalizadaCrítica (9.8)15%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security…
AnalizadaAlta (8.6)47%💥 PoCNetapp Oncommand InsightApache ActivemqApache JmeterXstream+1323/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed…
AnalizadaAlta (7.5)14%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security…
AnalizadaCrítica (9.8)14%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation…
AnalizadaCrítica (9.8)76%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation…
AnalizadaCrítica (9.9)72%💥 ExploitNetapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the…
AnalizadaCrítica (9.8)76%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation…
AnalizadaAlta (7.5)47%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1123/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information.…
AnalizadaCrítica (9.1)50%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1123/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information.…
AnalizadaAlta (8.1)5.0%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+417/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
ModificadaAlta (8.1)4.1%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+417/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
ModificadaAlta (8.1)4.1%💥 PoCNetapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+417/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
ModificadaAlta (8.1)17%💥 PoCNetapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+397/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
ModificadaAlta (8.1)8.8%💥 PoCFasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+416/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.
ModificadaAlta (8.1)4.2%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+416/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.
ModificadaAlta (8.1)4.2%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+416/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.