Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

942 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.59%—3dweb 360 Javascript ViewerAI9/12/202417/6/2026
Missing Authorization vulnerability in 3DWeb 360 Javascript Viewer 360deg-javascript-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 360 Javascript Viewer: from n/a through <= 1.7.11.
AplazadaBaja (2.1)0.21%—Sigstore-javaAI5/12/202417/6/2026
sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a bundle provides a invalid signature for a checkpoint. This bug impacts clients using any variation of KeylessVerifier.verify(). Currently checkpoints are only used…
AplazadaMedia (5.5)0.10%—Sigstore-javaAI26/11/202417/6/2026
sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is presented as proof of inclusion into a transparency log. This bug impacts clients using any variation of…
AnalizadaMedia (5.2)0.13%—Google Firebase Javascript SDK18/11/202417/6/2026
Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it…
AnalizadaMedia (4.3)0.29%—Geeeeeeeek Java Shop15/11/202417/6/2026
A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.
ModificadaMedia (6.5)0.50%—Geeeeeeeek Java Shop15/11/202417/6/2026
java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.
AplazadaMedia (5.3)0.31%—SAP Netweaver AS JavaAI12/11/202417/6/2026
SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability.
AplazadaMedia (4.7)0.13%—SAP Netweaver JavaAISAP Software Update ManagerAI12/11/202417/6/2026
In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the credentials from the logs. This leads to…
AplazadaMedia (6.5)0.27%—SAP Netweaver AS JavaAI12/11/202417/6/2026
Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.
AnalizadaBaja (2.3)0.45%—Mariazevedo88 Travels-java-api6/11/202417/6/2026
A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\src\main\java\io\github\mariazevedo88\travelsjavaapi\filters\JwtAuthenticationTokenFilter.java of the component JWT Secret…
ModificadaAlta (7.5)0.63%—Linlinjava Litemall19/9/202417/6/2026
A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminOrderController.java.
AnalizadaAlta (8.7)2.8%—Google ProtobufGoogle Protobuf-javaGoogle Protobuf-javaliteGoogle Protobuf-kotlin+419/9/202417/6/2026
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map…
AplazadaMedia (6)0.17%—SAP Netweaver AS FOR JavaAI10/9/202417/6/2026
SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.
AplazadaMedia (4.8)0.24%—SAP Netweaver AS JavaAI10/9/202417/6/2026
Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability.
AnalizadaMedia (5.3)0.48%—Matrix Javascript SDK20/8/202417/6/2026
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This method is public but…
ModificadaMedia (5.9)0.45%—IBM Java SDK14/8/202417/6/2026
The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads.
AnalizadaAlta (8.2)0.54%—SAP BEX WEB Java Runtime Export WEB Service13/8/202417/6/2026
BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source. An attacker can retrieve information from the SAP ADS system and exhaust the number of XMLForm service which makes the SAP ADS rendering (PDF creation) unavailable. This affects the confidentiality…
AnalizadaMedia (6.3)0.21%—SAP Netweaver AbapSAP Netweaver JavaSAP Content ServerSAP WEB Dispatcher13/8/202417/6/2026
Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the…
AplazadaAlta (7.5)0.51%—Oracle Java PlatformAI6/8/202417/6/2026
Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If this vulnerability is exploited, the product may be affected by some known TLS1.0 and TLS1.1 vulnerabilities. As for the specific products/models/versions of MFPs and printers that contain JavaTM…
AnalizadaMedia (5)0.28%—Biscuitsec Biscuit-java1/8/202417/6/2026
biscuit-java is the java implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a ThirdPartyBlock request can be sent, providing only the necessary info to…
AplazadaMedia (5.3)0.94%—Graphql-java Graphql JavaAI30/7/202417/6/2026
GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.
AplazadaMedia (5.3)0.37%—ADD Admin JavascriptAI27/7/202417/6/2026
The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web…
AplazadaAlta (8.9)0.39%—DnsjavaAI22/7/202417/6/2026
dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0.
AnalizadaMedia (5.3)0.47%—Linlinjava Litemall2/7/202417/6/2026
A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file AdminGoodscontroller.java. The manipulation of the argument goodsId/goodsSn/name leads to sql injection. The attack can be launched remotely. The exploit has been…
AplazadaAlta (7.5)0.59%—Cyclonedx Core JavaAI28/6/202417/6/2026
The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX Bill of Materials in XML format, _cyclonedx-core-java_ leverages XPath expressions to determine the schema version of the BOM. The…