Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
613 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 56% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+15 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and… | |
| Modificada | Alta (7.5) | 87% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+18 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a… | |
| Modificada | Alta (7.5) | 83% | — | Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+24 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can… | |
| Modificada | Alta (7.5) | 82% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+16 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU. | |
| Modificada | Alta (7.5) | 60% | 💥 PoC | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+16 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to… | |
| Modificada | Media (4.9) | 3.4% | — | OpenldapCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+5 | 26/7/2019 | 17/6/2026 | An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from… | |
| Modificada | Media (6.2) | 0.35% | — | Mcafee Data Loss Prevention Endpoint | 25/7/2019 | 17/6/2026 | Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows physical local user to bypass the Windows lock screen via DLPe processes being killed just prior to the screen being locked or when the screen is locked. The attacker requires physical access to… | |
| Modificada | Alta (8.2) | 0.33% | — | Mcafee Data Loss Prevention Endpoint | 24/7/2019 | 17/6/2026 | Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to the DLPe log folder allowing privileged users to create symbolic links. | |
| Modificada | Media (6.5) | 0.71% | — | Mcafee Data Loss Prevention Endpoint | 24/7/2019 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy, which is exported and opened… | |
| Modificada | Media (6.1) | 0.83% | — | Mcafee Data Loss Prevention Endpoint | 24/7/2019 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows unauthenticated remote user to trigger specially crafted JavaScript to render in the ePO UI via a carefully crafted upload to a remote… | |
| Modificada | Baja (3.7) | 3.4% | — | Oracle JDKOracle JREOpensuse LeapHP XP7 Command View+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JCE). The supported version that is affected is Java SE: 8u212. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can… | |
| Modificada | Media (4.8) | 2.3% | — | Oracle JDKOracle JREDebian LinuxOpensuse Leap+9 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple… | |
| Modificada | Media (5.3) | 4.4% | — | Oracle JDKOracle JREDebian LinuxCanonical Ubuntu Linux+9 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Baja (3.1) | 2.7% | — | Oracle JDKOracle JREMcafee Epolicy OrchestratorHP XP7 Command View+1 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple… | |
| Modificada | Media (5.3) | 4.4% | — | Oracle JDKOracle JRECanonical Ubuntu LinuxOpensuse Leap+9 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Media (5.1) | 0.46% | — | Oracle JDKOracle JREDebian LinuxCanonical Ubuntu Linux+3 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u221, 8u212 and 11.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful… | |
| Modificada | Media (6.7) | 0.32% | — | Mcafee Agent | 18/7/2019 | 17/6/2026 | Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory. | |
| Modificada | Media (4.9) | 1.1% | — | Mcafee Epolicy Orchestrator | 3/7/2019 | 17/6/2026 | Information Disclosure vulnerability in the Agent Handler in McAfee ePolicy Orchestrator (ePO) 5.9.x and 5.10.0 prior to 5.10.0 update 4 allows remote unauthenticated attacker to view sensitive information in plain text via sniffing the traffic between the Agent Handler and the SQL server. | |
| Modificada | Alta (8.8) | 1.7% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via specially crafted input. | |
| Modificada | Alta (7.2) | 2.0% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters. | |
| Modificada | Alta (7.2) | 2.0% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters. | |
| Modificada | Media (6.5) | 1.2% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users via specially crafted parameters. | |
| Modificada | Alta (8.8) | 0.98% | — | Mcafee Enterprise Security Manager | 27/6/2019 | 17/6/2026 | Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain access to a core system component via incorrect access control. | |
| Modificada | Media (4.8) | 0.62% | — | Mcafee Network Security Manager | 15/5/2019 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) Prior to 9.1 Update 5 allows an authenticated administrator to embed an XSS in the administrator interface via a specially crafted custom rule containing HTML. | |
| Modificada | Alta (7.5) | 0.76% | — | Mcafee Endpoint Security | 15/5/2019 | 17/6/2026 | Protection Mechanism Failure in the Firewall in McAfee Endpoint Security (ENS) 10.x prior to 10.6.1 May 2019 update allows context-dependent attackers to circumvent ENS protection where GTI flagged IP addresses are not blocked by the ENS Firewall via specially crafted malicious sites where the GTI reputation is… |