Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

269 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)4.0%—Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node SupplementaryRedhat Enterprise Linux Server+93/6/201617/6/2026
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController…
ModificadaMedia (5.6)3.9%—Suse Linux Enterprise ServerSuse Linux Enterprise Software Development KITIBM Java SDKRedhat Satellite+924/5/201617/6/2026
Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors.
AnalizadaCrítica (9.8)92%⚠ Explotación activaOracle JDKOracle JREOracle JrockitOracle Linux+3421/4/201617/6/2026
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
ModificadaMedia (6.1)1.6%—Redhat SatelliteRedhat Spacewalk-java14/4/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot…
ModificadaMedia (6.1)1.1%—Redhat Satellite14/4/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the list_1680466951_oldfilterval parameter to systems/PhysicalList.do or (2) unspecified vectors involving systems/VirtualSystemsList.do.
ModificadaMedia (5.4)1.2%—Redhat SatelliteRedhat Spacewalk-java14/4/201617/6/2026
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
ModificadaMedia (4.2)1.2%—Theforeman ForemanRedhat Satellite11/4/201617/6/2026
Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to delete reports from arbitrary hosts via…
ModificadaBaja (2.1)0.48%—IBM Java 2 SDKIBM Java SDKRedhat SatelliteRedhat Enterprise Linux Desktop+57/12/201517/6/2026
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache.
ModificadaAlta (7.5)10%—LibpngFedoraproject FedoraOpensuse LeapOpensuse+1613/11/201517/6/2026
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other…
AnalizadaMedia (5.3)14%⚠ Explotación activaOracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+1722/10/201517/6/2026
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
ModificadaAlta (7.2)0.92%💥 ExploitVboxcomm Satellite Express Protocol21/9/201517/6/2026
The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call.
AnalizadaCrítica (9.8)25%⚠ Explotación activaOracle JDKOracle JRECanonical Ubuntu LinuxDebian Linux+1716/7/201517/6/2026
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.
ModificadaAlta (7.5)2.7%—Redhat Network SatelliteSuse Manager14/5/201517/6/2026
XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified impact via unknown vectors.
ModificadaBaja (3.7)74%—Oracle Communications Application Session ControllerOracle Communications Policy ManagementOracle Http ServerOracle Integrated Lights OUT Manager Firmware+571/4/201517/6/2026
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally…
ModificadaBaja (3.5)1.5%—Redhat SatelliteRedhat SpacewalkSuse Manager15/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allows remote authenticated users to inject arbitrary web script or HTML via the System Groups field.
ModificadaBaja (3.5)1.5%—Redhat Network SatelliteRedhat SpacewalkSuse Manager15/1/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the REST API.
ModificadaMedia (4.3)1.8%—Redhat SatelliteRedhat Satellite With Embedded OracleRedhat Spacewalk-javaSuse Manager Server+13/11/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) kickstart/cobbler/CustomSnippetList.do, (2) channels/software/Entitlements.do, or (3)…
ModificadaMedia (4.3)1.8%—Redhat SatelliteRedhat Satellite With Embedded OracleRedhat Spacewalk-javaSuse Manager+122/9/201417/6/2026
Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.
ModificadaMedia (6.5)48%💥 ExploitRedhat Network SatelliteTheforeman Katello17/4/201416/6/2026
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.
ModificadaMedia (6)3.1%—Redhat Network ProxyRedhat SatelliteRedhat Spacewalk-java15/4/201416/6/2026
The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.
ModificadaMedia (4.3)1.8%—Redhat SatelliteRedhat Spacewalk-java1/4/201416/6/2026
CRLF injection vulnerability in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 5.6 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via the return_url parameter.
ModificadaMedia (4.3)1.7%—Redhat SatelliteRedhat Satellite 5 Managed DBRedhat Spacewalk-javaRedhat Spacewalk-web+114/2/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) whereCriteria variable in a software channels search; (2) end_year, (3) start_hour, (4) end_am_pm, (5) end_day, (6) end_hour, (7)…
ModificadaBaja (3.5)1.6%—Redhat Satellite14/2/201416/6/2026
Cross-site scripting (XSS) vulnerability in account/EditAddress.do in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allows remote attackers to inject arbitrary web script or HTML via the type parameter.
ModificadaBaja (3.5)1.6%—Redhat SatelliteRedhat Satellite 5 Managed DBRedhat Spacewalk-java14/2/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) content values of a note in a system.addNote XML-RPC call.
ModificadaMedia (4.9)1.6%—Redhat Network ProxyRedhat Satellite5/2/201416/6/2026
A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrators can exploit this by reading server logs and emails, leading to the unauthorized disclosure of…
Orbitaley — Vulnerabilidades