Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
942 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.59% | — | 3dweb 360 Javascript ViewerAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in 3DWeb 360 Javascript Viewer 360deg-javascript-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 360 Javascript Viewer: from n/a through <= 1.7.11. | |
| Aplazada | Baja (2.1) | 0.21% | — | Sigstore-javaAI | 5/12/2024 | 17/6/2026 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a bundle provides a invalid signature for a checkpoint. This bug impacts clients using any variation of KeylessVerifier.verify(). Currently checkpoints are only used… | |
| Aplazada | Media (5.5) | 0.10% | — | Sigstore-javaAI | 26/11/2024 | 17/6/2026 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is presented as proof of inclusion into a transparency log. This bug impacts clients using any variation of… | |
| Analizada | Media (5.2) | 0.13% | — | Google Firebase Javascript SDK | 18/11/2024 | 17/6/2026 | Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it… | |
| Analizada | Media (4.3) | 0.29% | — | Geeeeeeeek Java Shop | 15/11/2024 | 17/6/2026 | A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function. | |
| Modificada | Media (6.5) | 0.50% | — | Geeeeeeeek Java Shop | 15/11/2024 | 17/6/2026 | java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter. | |
| Aplazada | Media (5.3) | 0.31% | — | SAP Netweaver AS JavaAI | 12/11/2024 | 17/6/2026 | SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability. | |
| Aplazada | Media (4.7) | 0.13% | — | SAP Netweaver JavaAISAP Software Update ManagerAI | 12/11/2024 | 17/6/2026 | In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the credentials from the logs. This leads to… | |
| Aplazada | Media (6.5) | 0.27% | — | SAP Netweaver AS JavaAI | 12/11/2024 | 17/6/2026 | Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application. | |
| Analizada | Baja (2.3) | 0.45% | — | Mariazevedo88 Travels-java-api | 6/11/2024 | 17/6/2026 | A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\src\main\java\io\github\mariazevedo88\travelsjavaapi\filters\JwtAuthenticationTokenFilter.java of the component JWT Secret… | |
| Modificada | Alta (7.5) | 0.63% | — | Linlinjava Litemall | 19/9/2024 | 17/6/2026 | A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminOrderController.java. | |
| Analizada | Alta (8.7) | 2.8% | — | Google ProtobufGoogle Protobuf-javaGoogle Protobuf-javaliteGoogle Protobuf-kotlin+4 | 19/9/2024 | 17/6/2026 | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map… | |
| Aplazada | Media (6) | 0.17% | — | SAP Netweaver AS FOR JavaAI | 10/9/2024 | 17/6/2026 | SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data. | |
| Aplazada | Media (4.8) | 0.24% | — | SAP Netweaver AS JavaAI | 10/9/2024 | 17/6/2026 | Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability. | |
| Analizada | Media (5.3) | 0.48% | — | Matrix Javascript SDK | 20/8/2024 | 17/6/2026 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This method is public but… | |
| Modificada | Media (5.9) | 0.45% | — | IBM Java SDK | 14/8/2024 | 17/6/2026 | The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads. | |
| Analizada | Alta (8.2) | 0.54% | — | SAP BEX WEB Java Runtime Export WEB Service | 13/8/2024 | 17/6/2026 | BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source. An attacker can retrieve information from the SAP ADS system and exhaust the number of XMLForm service which makes the SAP ADS rendering (PDF creation) unavailable. This affects the confidentiality… | |
| Analizada | Media (6.3) | 0.21% | — | SAP Netweaver AbapSAP Netweaver JavaSAP Content ServerSAP WEB Dispatcher | 13/8/2024 | 17/6/2026 | Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the… | |
| Aplazada | Alta (7.5) | 0.51% | — | Oracle Java PlatformAI | 6/8/2024 | 17/6/2026 | Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If this vulnerability is exploited, the product may be affected by some known TLS1.0 and TLS1.1 vulnerabilities. As for the specific products/models/versions of MFPs and printers that contain JavaTM… | |
| Analizada | Media (5) | 0.28% | — | Biscuitsec Biscuit-java | 1/8/2024 | 17/6/2026 | biscuit-java is the java implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a ThirdPartyBlock request can be sent, providing only the necessary info to… | |
| Aplazada | Media (5.3) | 0.94% | — | Graphql-java Graphql JavaAI | 30/7/2024 | 17/6/2026 | GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions. | |
| Aplazada | Media (5.3) | 0.37% | — | ADD Admin JavascriptAI | 27/7/2024 | 17/6/2026 | The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web… | |
| Aplazada | Alta (8.9) | 0.39% | — | DnsjavaAI | 22/7/2024 | 17/6/2026 | dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0. | |
| Analizada | Media (5.3) | 0.47% | — | Linlinjava Litemall | 2/7/2024 | 17/6/2026 | A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file AdminGoodscontroller.java. The manipulation of the argument goodsId/goodsSn/name leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Alta (7.5) | 0.59% | — | Cyclonedx Core JavaAI | 28/6/2024 | 17/6/2026 | The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX Bill of Materials in XML format, _cyclonedx-core-java_ leverages XPath expressions to determine the schema version of the BOM. The… |