Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

942 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.32%—Joey-zhou Xiaozhi-esp32-server-javaAI7/4/202517/6/2026
A vulnerability has been found in joey-zhou xiaozhi-esp32-server-java up to a14fe8115842ee42ab5c7a51706b8a85db5200b7 and classified as critical. This vulnerability affects the function update of the file /api/user/update. The manipulation of the argument state leads to sql injection. The attack can be initiated…
AnalizadaCrítica (10)44%—Apache Parquet Java1/4/202517/6/2026
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.
AplazadaMedia (6.5)0.22%—Jacob Allred Infusionsoft WEB Form JavascriptAI31/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacob Allred Infusionsoft Web Form JavaScript infusionsoft-web-form-javascript allows Stored XSS.This issue affects Infusionsoft Web Form JavaScript: from n/a through <= 1.1.1.
AplazadaMedia (5.3)0.36%—Crmeb JavaAI17/3/202517/6/2026
A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the file WeChatMessageController.java. The manipulation leads to xml external entity reference. The attack may be launched remotely. The exploit has been disclosed to the…
AplazadaMedia (4.3)0.14%—Ed25519 JavaAI13/3/202517/6/2026
The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message Attacks) property. This allows attackers to create new valid signatures different from previous signatures for a known…
AnalizadaAlta (7.5)0.71%—Ruby-lang Javascript Object Notation12/3/202517/6/2026
JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document could cause an out of bound read, most likely resulting in a crash. Versions prior to 2.10.0 are not vulnerable. Version 2.10.2 fixes the problem. No known workarounds are available.
AplazadaMedia (5.4)0.22%—SAP Netweaver Application Server JavaAI11/3/202517/6/2026
User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality, hence leading to information disclosure or unauthorized data…
AplazadaMedia (5.5)0.23%—Cloudevents Java SDKAI21/2/202517/6/2026
An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows attackers to access sensitive information via supplying a crafted XML-formatted event message.
AplazadaCrítica (9.2)0.95%—Pingidentity Pingam Java Policy AgentAI20/2/202517/6/2026
Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: through 5.10.3, through 2023.11.1, through 2024.9.
AplazadaMedia (4.3)0.26%—SAP Netweaver Application Server JavaAI11/2/202517/6/2026
SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, even though they may not need it. These XML files are not entirely…
AplazadaMedia (5.4)0.27%—SAP Netweaver Application Server JavaAI11/2/202517/6/2026
SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the…
AnalizadaMedia (4.8)0.36%—Beian.miit Cool-admin-java10/2/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field.
AnalizadaAlta (7.2)0.85%—Beian.miit Cool-admin-java10/2/202517/6/2026
An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code via uploading a crafted file.
AplazadaMedia (5.4)1.1%—Verizon Serialize-javascriptAI10/2/20251/10/2026
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser,…
AplazadaCrítica (9.3)23%—DJL Deep Java LibraryAI29/1/202517/6/2026
A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations.
AplazadaMedia (6.5)0.37%—Matthias.wagner Caching-compatible-cookie-optin-and-javascriptAI24/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matthias.wagner Caching Compatible Cookie Opt-In and JavaScript caching-compatible-cookie-optin-and-javascript allows Stored XSS.This issue affects Caching Compatible Cookie Opt-In and JavaScript: from n/a through <=…
AnalizadaMedia (4.2)0.25%—Oracle Java Virtual Machine21/1/202517/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.25, 21.3-21.16 and 23.4-23.6. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.…
AplazadaMedia (5.3)0.46%—Ujjavaljani Copy Move PostsAI16/1/202517/6/2026
Missing Authorization vulnerability in ujjavaljani Copy Move Posts copy-move-posts.This issue affects Copy Move Posts: from n/a through <= 1.6.
AplazadaMedia (6.3)0.26%—SAP Netweaver Application Server JavaAI14/1/202517/6/2026
Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo connection entries, which are used for remote function calls from or to the application server. This could lead to low impact on confidentiality, integrity, and…
AplazadaMedia (4.8)0.24%—SAP Netweaver AS JavaAI14/1/202517/6/2026
SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.
AplazadaMedia (6)0.20%—SAP GUI FOR JavaAI14/1/202517/6/2026
SAP GUI for Java saves user input on the client PC to improve usability. An attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from…
AplazadaCrítica (9.8)0.69%—Wukongcrm-javaAI3/1/202517/6/2026
An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.
ModificadaAlta (8.6)0.59%—Amazon WEB Services Redshift Java Database Connectivity Driver24/12/202417/6/2026
A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.
AplazadaAlta (8.6)0.56%—Ucum-javaAI13/12/202417/6/2026
Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumEssenceService is vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where ucum…
AplazadaMedia (4.4)0.37%—360 Javascript ViewerAI12/12/202417/6/2026
The 360 Javascript Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ref’ parameter in all versions up to, and including, 1.7.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject…