Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
482 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 1.1% | — | Solarwinds NetpathSolarwinds Network Performance MonitorSolarwinds Orion Platform | 25/2/2020 | 17/6/2026 | SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen. | |
| Modificada | Media (5.4) | 1.4% | — | Solarwinds Network Performance Monitor Orion Platform 2018 NetpathSolarwinds Network Performance Monitor Orion Platform 2018 NPM | 17/2/2020 | 17/6/2026 | SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT. | |
| Modificada | Baja (3.7) | 4.2% | — | Oracle JDKOracle JREOracle OpenjdkDebian Linux+19 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241 and 8u231; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java… | |
| Modificada | Baja (3.7) | 4.0% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+19 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of… | |
| Modificada | Alta (8.1) | 4.9% | — | Oracle Commerce Experience ManagerOracle Commerce Guided SearchOracle GraalvmOracle JDK+23 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Media (6.8) | 4.3% | — | Oracle JDKOracle JREOracle OpenjdkDebian Linux+19 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise… | |
| Modificada | Media (4.8) | 3.0% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+20 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Baja (3.7) | 3.2% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+20 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise… | |
| Modificada | Media (5.9) | 3.3% | — | Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+10 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result… | |
| Modificada | Baja (3.7) | 4.0% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+20 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Alta (7.8) | 0.42% | — | IBM DB2 High Performance Unload Load | 12/12/2019 | 17/6/2026 | IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted search path vulnerability. By using a executable file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 168298. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (7.8) | 0.44% | — | IBM DB2 High Performance Unload Load | 22/10/2019 | 17/6/2026 | IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 165481. | |
| Modificada | Alta (8.8) | 2.5% | — | Broadcom CA Performance ManagementBroadcom Network Operations | 17/10/2019 | 17/6/2026 | CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security. | |
| Modificada | Media (4) | 0.67% | — | Oracle Hyperion Enterprise Performance Management Architect | 16/10/2019 | 17/6/2026 | Vulnerability in the Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Modeling). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Profitability and Cost Management.… | |
| Modificada | Media (6.5) | 3.8% | — | Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jOracle Application Performance Management+14 | 18/9/2019 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys. | |
| Modificada | Media (6.5) | 2.5% | — | Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jOracle Application Performance Management+12 | 18/9/2019 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys. | |
| Modificada | Media (6.5) | 1.7% | — | Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jMcafee Threat Intelligence Exchange Server+12 | 18/9/2019 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key. | |
| Modificada | Media (6.1) | 1.2% | — | IBM Application Performance Management | 17/9/2019 | 17/6/2026 | IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the… | |
| Modificada | Media (5.6) | 0.61% | — | Linux KernelNetapp Active IQ Performance Analytics ServicesNetapp Service ProcessorDebian Linux+2 | 4/9/2019 | 17/6/2026 | A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre… | |
| Modificada | Alta (7.8) | 0.34% | — | IBM DB2 High Performance Unload Load | 26/8/2019 | 17/6/2026 | IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are setuid root and have built-in options that allow an low privileged user the ability to load arbitrary db2 libraries from a privileged context. This results in arbitrary… | |
| Modificada | Alta (7.8) | 0.45% | — | IBM DB2 High Performance Unload Load | 26/8/2019 | 17/6/2026 | IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary which trusts the PATH environment variable. A low privileged user can execute arbitrary commands as root by altering the PATH variable to point to a user controlled… | |
| Modificada | Alta (7.3) | 28% | — | Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+56 | 20/8/2019 | 25/8/2026 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | |
| Modificada | Media (6.1) | 0.91% | — | Greg's High Performance SEO Project Greg's High Performance SEO | 20/8/2019 | 17/6/2026 | The gregs-high-performance-seo plugin before 1.6.2 for WordPress has XSS in the context of an old browser. | |
| Modificada | Media (4.6) | 0.72% | — | Linux KernelNetapp Active IQ Performance Analytics ServicesNetapp Active IQ Unified ManagerNetapp Data Availability Services+4 | 16/8/2019 | 17/6/2026 | drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor. |