Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 4.5% | 💥 PoC | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageDebian Linux+10 | 16/6/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity). | |
| Analizada | Alta (8.1) | 8.6% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+8 | 14/6/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill). | |
| Analizada | Alta (8.1) | 8.1% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageDebian Linux+9 | 14/6/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2). | |
| Modificada | Alta (8.1) | 4.5% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageDebian Linux+11 | 14/6/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and… | |
| Modificada | Alta (8.6) | 1.1% | — | Juniper JunosJuniper Junos OS Evolved | 15/4/2020 | 17/6/2026 | In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos OS and Junos OS Evolved devices to advertise an invalid BGP UPDATE message to other peers, causing the other peers to terminate the established BGP session, creating a Denial of Service (DoS) condition. For example,… | |
| Modificada | Alta (7.5) | 1.3% | — | Juniper JunosJuniper Junos OS Evolved | 8/4/2020 | 17/6/2026 | The FPC (Flexible PIC Concentrator) of Juniper Networks Junos OS and Junos OS Evolved may restart after processing a specific IPv4 packet. Only packets destined to the device itself, successfully reaching the RE through existing edge and control plane filtering, will be able to cause the FPC restart. When this issue… | |
| Modificada | Alta (7.5) | 1.4% | — | Juniper Junos OS Evolved | 8/4/2020 | 17/6/2026 | A vulnerability in Juniper Networks Junos OS Evolved may allow an attacker to cause a Denial of Service (DoS) by sending a high rate of specific packets to the device, resulting in a pfemand process crash. The pfemand process is responsible for packet forwarding on the device. By continuously sending the packet flood,… | |
| Modificada | Media (5.5) | 0.32% | — | Juniper Junos OS Evolved | 8/4/2020 | 17/6/2026 | A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files. This issue affects all versions of Junos OS Evolved prior to 19.1R1. | |
| Modificada | Media (5.5) | 0.32% | — | Juniper Junos OS Evolved | 8/4/2020 | 17/6/2026 | A local, authenticated user with shell can view sensitive configuration information via the ev.ops configuration file. This issue affects all versions of Junos OS Evolved prior to 19.2R1. | |
| Modificada | Media (5.5) | 0.32% | — | Juniper Junos OS Evolved | 8/4/2020 | 17/6/2026 | A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1. | |
| Modificada | Media (5.5) | 0.32% | — | Juniper Junos OS Evolved | 8/4/2020 | 17/6/2026 | A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1. | |
| Modificada | Media (5.5) | 0.32% | — | Juniper Junos OS Evolved | 8/4/2020 | 17/6/2026 | A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1. | |
| Modificada | Alta (8.1) | 5.8% | — | Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated Storage+14 | 7/4/2020 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly). | |
| Analizada | Alta (8.1) | 3.7% | — | Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated Storage+17 | 7/4/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop). | |
| Analizada | Alta (8.8) | 6.3% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+28 | 31/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). | |
| Analizada | Alta (8.8) | 3.6% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 31/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy). | |
| Modificada | Alta (8.8) | 3.6% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+21 | 31/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms). | |
| Modificada | Alta (8.8) | 3.6% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 26/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane. | |
| Modificada | Alta (8.8) | 3.6% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 26/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). | |
| Modificada | Crítica (9.8) | 9.5% | — | Quest Foglight Evolve | 23/3/2020 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the __service__ user account. The product contains a hard-coded password for this account. An… | |
| Modificada | Alta (8.8) | 8.0% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 18/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus). | |
| Modificada | Alta (8.8) | 3.1% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 18/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms). | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerDebian LinuxOracle Agile Product Lifecycle Management+21 | 2/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core). | |
| Modificada | Crítica (9.8) | 18% | 💥 Exploit | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerDebian LinuxOracle Autovue FOR Agile Product Lifecycle Management+12 | 2/3/2020 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap). | |
| Modificada | Crítica (9.8) | 4.6% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerDebian LinuxOracle Agile Product Lifecycle Management+27 | 2/3/2020 | 7/10/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config). |