Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
942 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.78% | — | Deepjava LibraryAI | 17/6/2024 | 17/6/2026 | DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files directly into the system, overwriting system files. This is fixed in DJL 0.28.0 and patched in DJL Large Model Inference containers… | |
| Modificada | Alta (7.5) | 0.54% | — | SAP Netweaver Application Server Java | 11/6/2024 | 17/6/2026 | Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact on the availability of the application. | |
| Modificada | Media (5.3) | 0.33% | — | SAP Netweaver Application Server Java | 11/6/2024 | 17/6/2026 | SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application. | |
| Modificada | Alta (8.8) | 0.92% | — | DJL Deep Java Library | 6/6/2024 | 17/6/2026 | A TarSlip vulnerability exists in the deepjavalibrary/djl, affecting version 0.26.0 and fixed in version 0.27.0. This vulnerability allows an attacker to manipulate file paths within tar archives to overwrite arbitrary files on the target system. Exploitation of this vulnerability could lead to remote code execution,… | |
| Analizada | Alta (7.8) | 0.35% | — | Deobfuscate Javascript Deobfuscator | 31/5/2024 | 17/6/2026 | javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targeting expression simplification can lead to code execution. This issue has been patched in version 1.1.0. Users are advised to update. Users unable to upgrade should disable the expression simplification… | |
| Analizada | Media (6.5) | 1.7% | — | Microsoft Powerbi-javascript | 14/5/2024 | 17/6/2026 | Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability | |
| Aplazada | Alta (8.1) | 0.92% | — | Owasp CyclonedxAICyclonedx JavascriptAI | 14/5/2024 | 17/6/2026 | The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1. | |
| Aplazada | Media (5.9) | 0.90% | — | Bouncycastle Java TLS APIAIBouncycastle Jsse ProviderAI | 14/5/2024 | 17/6/2026 | An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. | |
| Aplazada | Alta (7.5) | 1.1% | — | Bouncycastle BC JavaAIBouncycastle BC Java LTSAIBouncycastle BC FJAAIBouncycastle BC C Sharp NETAI | 14/5/2024 | 17/6/2026 | An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. | |
| Analizada | Alta (7.5) | 0.85% | — | IBM Java Software Development KIT | 14/5/2024 | 17/6/2026 | The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578. | |
| Analizada | Media (5.3) | 0.47% | — | Crmeb Java | 6/5/2024 | 17/6/2026 | crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController. | |
| Aplazada | Alta (7.5) | 0.77% | — | Bouncycastle Bouncy Castle JavaAIBouncycastle BcjsseAIBouncycastle Bouncy Castle Fips JavaAI | 3/5/2024 | 17/6/2026 | An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with… | |
| Analizada | Media (5.3) | 0.43% | — | Oracle Java Virtual Machine | 16/4/2024 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful… | |
| Aplazada | Media (4.3) | 0.50% | — | 360 Javascript ViewerAI | 9/4/2024 | 17/6/2026 | The 360 Javascript Viewer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and nonce exposure on several AJAX actions in all versions up to, and including, 1.7.12. This makes it possible for authenticated attackers, with subscriber access or higher, to update… | |
| Aplazada | Alta (8.8) | 0.40% | — | SAP Netweaver AS JavaAI | 9/4/2024 | 17/6/2026 | Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and… | |
| Modificada | Alta (8.1) | 0.85% | — | Crmeb Java | 28/3/2024 | 9/7/2026 | SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter. | |
| Analizada | Media (6.5) | 0.61% | — | Crmeb Java | 21/3/2024 | 17/6/2026 | SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people. | |
| Analizada | Crítica (9.1) | 1.6% | — | SAP Netweaver Application Server Java | 12/3/2024 | 17/6/2026 | SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity… | |
| Analizada | Alta (7.2) | 0.72% | — | Linlinjava Litemall | 27/2/2024 | 17/6/2026 | SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java component. | |
| Analizada | Alta (7.5) | 0.79% | — | Crmeb Java | 23/2/2024 | 17/6/2026 | SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component. | |
| Modificada | Alta (7.5) | 0.52% | — | SAP Netweaver Application Server Java | 13/2/2024 | 17/6/2026 | SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML file over the network, which when parsed will enable him to access sensitive files and data but not modify them. There are expansion limits in place so that availability… | |
| Modificada | Alta (8.8) | 0.52% | — | SAP Netweaver Application Server Java | 13/2/2024 | 17/6/2026 | The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them into the redirect URL. This results in Cross-Site Scripting (XSS) vulnerability, leading to a high impact on confidentiality and mild impact on… | |
| Modificada | Media (4.8) | 0.58% | — | Pixee Java Code Security Toolkit | 1/2/2024 | 17/6/2026 | The Pixee Java Code Security Toolkit is a set of security APIs meant to help secure Java code. `ZipSecurity#isBelowCurrentDirectory` is vulnerable to a partial-path traversal bypass. To be vulnerable to the bypass, the application must use toolkit version <=1.1.1, use ZipSecurity as a guard against path traversal, and… | |
| Modificada | Alta (8.8) | 0.68% | — | Clickhouse Java Libraries | 19/1/2024 | 14/7/2026 | Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs. This occurs when 'sslkey' is specified and… | |
| Modificada | Alta (8.2) | 0.36% | — | Ls1intum Artemis Java Test Sandbox | 19/1/2024 | 14/7/2026 | Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code. |