Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

523 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.9%—Redhat Jboss Enterprise Application Platform27/6/201817/6/2026
It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content for parsing. Doing a transform in JAXP requires the use of a…
ModificadaAlta (7.5)17%—Apache Http ServerRedhat Jboss Core ServicesCanonical Ubuntu LinuxNetapp Cloud Backup+118/6/201817/6/2026
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
ModificadaAlta (7.5)3.6%—Bouncycastle Bc-javaBouncycastle Fips Java APIDebian LinuxOracle API Gateway+165/6/201817/6/2026
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA…
ModificadaAlta (7.8)0.35%—Redhat Jboss Enterprise Application Platform22/5/201817/6/2026
Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.
ModificadaMedia (6.1)1.8%—Redhat UndertowRedhat Jboss Enterprise Application PlatformRedhat Virtualization Host21/5/201817/6/2026
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an…
ModificadaAlta (8.8)1.2%—InfinispanRedhat Jboss Data Grid15/5/201817/6/2026
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks.…
ModificadaMedia (6.5)2.6%—Redhat Jboss Enterprise Application PlatformRedhat Keycloak11/5/201817/6/2026
admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal…
ModificadaMedia (6.1)0.69%—Flexense Diskboss2/5/201817/6/2026
Flexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS.
ModificadaMedia (5.9)5.1%—Google GuavaRedhat Openshift Container PlatformRedhat OpenstackRedhat Satellite+1326/4/201817/6/2026
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the…
ModificadaMedia (5.9)2.0%—Redhat UndertowRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Virtualization18/4/201817/6/2026
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the…
ModificadaCrítica (9.8)16%—Apache Http ServerCanonical Ubuntu LinuxDebian LinuxNetapp Cloud Backup+926/3/201817/6/2026
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an…
ModificadaCrítica (9.8)15%—QOS Slf4jRedhat Jboss Enterprise Application PlatformRedhat VirtualizationRedhat Virtualization Host+920/3/201817/6/2026
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.
ModificadaAlta (7.5)3.0%—Redhat Jboss Wildfly Application Server12/3/201817/6/2026
Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections. It was found that this cache can easily exploited to fill memory with garbage, up to "max-headers" (default 200) *…
ModificadaMedia (5.3)1.1%—Redhat Jboss Enterprise Application Platform9/3/201817/6/2026
Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. An attacker could exploit this vulnerability resulting in a denial of service attack.
ModificadaAlta (7.5)6.0%—Apache ArtemisRedhat HornetqRedhat Jboss Enterprise Application Platform7/3/201817/6/2026
It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryError.
ModificadaMedia (5.9)15%—Cavium Nitrox SSL SDKCavium Nitrox V SSL SDKCavium Octeon SDKCavium Octeon SSL SDK+105/3/201817/6/2026
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
ModificadaMedia (5.9)17%💥 PoCApache TomcatRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerDebian Linux+628/2/201817/6/2026
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore,…
ModificadaCrítica (9.8)20%💥 PoCFasterxml Jackson-databindDebian LinuxOracle Communications Billing AND Revenue ManagementOracle Communications Instant Messaging Server+126/2/201817/6/2026
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper,…
ModificadaAlta (7.5)16%💥 ExploitJboss-remotingRedhat Jboss Enterprise Application Platform15/2/201817/6/2026
A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.
ModificadaCrítica (9.8)38%💥 PoCFasterxml Jackson-databindDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+176/2/201817/6/2026
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
ModificadaCrítica (9.8)8.4%—Fasterxml Jackson-databindDebian LinuxRedhat Openshift Container PlatformRedhat Satellite+206/2/201817/6/2026
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting…
ModificadaAlta (8.1)0.46%—Flexense Diskboss2/2/201817/6/2026
An issue was discovered in Flexense DiskBoss 8.8.16 and earlier. Due to the usage of plaintext information from the handshake as input for the encryption key used for the encryption of the rest of the session, the server and client disclose sensitive information, such as the authentication credentials, to any…
ModificadaAlta (7.5)1.6%—Redhat Jboss Enterprise Application Platform24/1/201817/6/2026
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
ModificadaMedia (5.5)0.51%💥 PoCRedhat Jboss Wildfly Application ServerRedhat Jboss Enterprise Application Platform24/1/201817/6/2026
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
ModificadaAlta (8.1)7.2%—Fasterxml Jackson-databindDebian LinuxRedhat Openshift Container PlatformRedhat Virtualization+522/1/201817/6/2026
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.