Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
359 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Eclipse Tinydtls | 8/7/2021 | 17/6/2026 | Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic. | |
| Modificada | Crítica (9.8) | 58% | 💥 Exploit | Eclipse Business Intelligence AND Reporting Tools | 25/6/2021 | 17/6/2026 | In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance. | |
| Modificada | Baja (3.5) | 0.96% | 💥 PoC | Eclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+12 | 22/6/2021 | 17/6/2026 | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated.… | |
| Modificada | Media (5.3) | 78% | 💥 Exploit | Eclipse JettyDebian LinuxOracle Communications Cloud Native Core PolicyOracle Rest Data Services+4 | 9/6/2021 | 17/6/2026 | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive… | |
| Modificada | Media (6.5) | 10% | 💥 Exploit | Eclipse MojarraOracle Banking Enterprise Default ManagementOracle Banking PlatformOracle Communications Network Integrity+5 | 2/6/2021 | 17/6/2026 | Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter. | |
| Modificada | Media (5.3) | 2.1% | — | Eclipse Jakarta Expression LanguageQuarkusOracle Communications Cloud Native Core PolicyOracle Weblogic Server | 26/5/2021 | 17/6/2026 | In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid. | |
| Modificada | Media (5.5) | 0.87% | — | Eclipse JerseyOracle Communications Cloud Native Core PolicyOracle Communications Cloud Native Core Unified Data Repository | 22/4/2021 | 17/6/2026 | Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other… | |
| Modificada | Media (6.5) | 1.1% | — | Eclipse Openj9 | 21/4/2021 | 17/6/2026 | In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a user to call static methods or access static members without running the class initialization method, and may allow a user to observe… | |
| Modificada | Alta (7.8) | 0.23% | — | Tibco Messaging - Eclipse Mosquitto Distribution - Bridge | 14/4/2021 | 17/6/2026 | The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on… | |
| Modificada | Alta (7.8) | 0.23% | — | Tibco Messaging - Eclipse Mosquitto Distribution - Core | 14/4/2021 | 17/6/2026 | The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some… | |
| Modificada | Media (6.5) | 0.97% | — | Eclipse Mosquitto | 7/4/2021 | 17/6/2026 | In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted CONNACK message to the broker, a NULL pointer dereference would occur. | |
| Modificada | Alta (7.5) | 54% | 💥 PoC | Eclipse JettyOracle Autovue FOR Agile Product Lifecycle ManagementOracle Communications Cloud Native Core PolicyOracle Communications Element Manager+17 | 1/4/2021 | 17/6/2026 | In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. | |
| Modificada | Media (5.3) | 82% | 💥 Exploit | Eclipse JettyNetapp Cloud ManagerNetapp E-series Performance AnalyzerNetapp E-series Santricity OS Controller+13 | 1/4/2021 | 17/6/2026 | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive… | |
| Modificada | Baja (2.7) | 4.2% | — | Eclipse JettyFedoraproject FedoraApache IgniteApache Solr+19 | 1/4/2021 | 17/6/2026 | In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory. | |
| Modificada | Media (6.1) | 0.78% | — | Eclipse Theia | 12/3/2021 | 17/6/2026 | In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run. | |
| Modificada | Media (6.1) | 0.71% | — | Eclipse Theia | 12/3/2021 | 17/6/2026 | In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected. | |
| Modificada | Alta (7.8) | 0.34% | — | Eclipse Platform | 9/3/2021 | 17/6/2026 | In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process. | |
| Modificada | Media (5.3) | 78% | 💥 PoC | Eclipse JettyApache NifiApache SparkNetapp E-series Santricity OS Controller+12 | 26/2/2021 | 17/6/2026 | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values,… | |
| Modificada | Crítica (9.6) | 2.6% | — | Eclipse Theia | 24/2/2021 | 17/6/2026 | In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code. | |
| Modificada | Alta (7.5) | 0.85% | — | Eclipse Californium | 3/2/2021 | 17/6/2026 | In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshake failure with TLS parameter mismatch. The DTLS server… | |
| Modificada | Crítica (9.8) | 1.5% | — | Eclipse Openj9 | 21/1/2021 | 17/6/2026 | In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. | |
| Modificada | Alta (8.8) | 0.58% | — | Eclipse Vert.x-web | 20/1/2021 | 17/6/2026 | Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF token in the request with the CSRF token in the cookie, it compares the CSRF token in the cookie against a CSRF token that is stored in the session. An attacker does not even need to provide a CSRF token… | |
| Modificada | Alta (8.8) | 1.1% | — | Eclipse Hono | 14/1/2021 | 17/6/2026 | The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a specific device. The missing check involves verifying that the command target device is configured giving permission… | |
| Modificada | Media (6.1) | 0.83% | 💥 PoC | Eclipse Hawkbit | 14/1/2021 | 17/6/2026 | In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client. | |
| Modificada | Alta (7.1) | 0.51% | 💥 PoC | Eclipse CHE | 14/12/2020 | 17/6/2026 | A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, Theia IDE doesn't properly set the SameSite value, allowing a Cross-Site Request Forgery (CSRF) and consequently allowing a cross-site WebSocket hijack on Theia IDE. This flaw… |