Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1385 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)2.2%—Jetbrains KotlinOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Pricing Design Center25/2/202217/6/2026
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
ModificadaAlta (7.8)2.6%💥 PoCLinux KernelDebian LinuxNetapp H300eNetapp H300s+924/2/202217/6/2026
net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.
ModificadaAlta (8.8)4.1%—Cyrusimap Cyrus-saslDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+424/2/202217/6/2026
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
AnalizadaAlta (7.4)6.9%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+1718/2/202230/7/2026
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this…
ModificadaAlta (7.5)1.7%—TraefikOracle Communications Unified Inventory Management17/2/202217/6/2026
Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a request, the TLS configuration choice can be different than the router choice, which implies the use of a…
ModificadaCrítica (9.8)5.3%💥 PoCLinux KernelFedoraproject FedoraRedhat Enterprise LinuxOracle Communications Cloud Native Core Binding Support Function+216/2/202217/6/2026
A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.
ModificadaAlta (7.1)1.7%—Linux KernelRedhat 3scaleRedhat Virtualization HostFedoraproject Fedora+1516/2/202217/6/2026
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality,…
ModificadaAlta (7.5)7.9%—JenkinsXstreamFedoraproject FedoraDebian Linux+71/2/202217/6/2026
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input…
ModificadaMedia (5.5)0.53%—Linux KernelOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Exposure FunctionOracle Communications Cloud Native Core Policy31/1/202217/6/2026
A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of service.
ModificadaAlta (7)0.69%—Apache TomcatOracle Agile Engineering Data ManagementOracle Communications Cloud Native Core PolicyOracle Financial Services Crime AND Compliance Management Studio+327/1/202217/6/2026
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is…
ModificadaAlta (7.5)4.0%💥 PoCLibexpat Project LibexpatTenable NessusOracle Communications Metasolv SolutionDebian Linux+226/1/202217/6/2026
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
ModificadaMedia (6.5)12%—Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+2524/1/202225/8/2026
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version…
ModificadaCrítica (9.8)4.6%💥 PoCLibexpat Project LibexpatNetapp Clustered Data OntapNetapp Oncommand Workflow AutomationTenable Nessus+324/1/202217/6/2026
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
ModificadaCrítica (9.8)65%💥 PoCH2database H2Debian LinuxOracle Communications Cloud Native Core Console19/1/202217/6/2026
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
ModificadaMedia (6.6)0.67%—Oracle Communications Operations Monitor19/1/202217/6/2026
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (4.8)0.53%—Oracle Communications Operations Monitor19/1/202217/6/2026
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (6.6)0.67%—Oracle Communications Operations Monitor19/1/202217/6/2026
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (5.4)0.52%—Oracle Communications Operations Monitor19/1/202217/6/2026
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (6.6)0.67%—Oracle Communications Operations Monitor19/1/202217/6/2026
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (5.4)0.52%—Oracle Communications Operations Monitor19/1/202217/6/2026
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (5.4)0.52%—Oracle Communications Operations Monitor19/1/202217/6/2026
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (5.4)0.52%—Oracle Communications Operations Monitor19/1/202217/6/2026
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaAlta (7.2)1.2%—Oracle Communications Operations Monitor19/1/202217/6/2026
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
ModificadaCrítica (9.9)1.2%—Oracle Communications Billing AND Revenue Management19/1/202217/6/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
ModificadaCrítica (10)2.4%—Oracle Communications Billing AND Revenue Management19/1/202217/6/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Webservices Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…