Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1092 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.3% | — | Genivia GsoapOracle Communications Diameter Signaling RouterOracle Communications Eagle Application ProcessorOracle Communications Eagle LNP Application Processor+2 | 25/3/2021 | 17/6/2026 | A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Media (5.5) | 0.50% | — | SqliteOracle Communications Network Charging AND ControlEnterprise Manager FOR Oracle DatabaseOracle JD Edwards Enterpriseone Tools+3 | 23/3/2021 | 17/6/2026 | A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system… | |
| Analizada | Crítica (9.1) | 82% | 💥 Exploit | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to… | |
| Analizada | Crítica (9.8) | 15% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security… | |
| Analizada | Alta (8.6) | 47% | 💥 PoC | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+13 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed… | |
| Analizada | Alta (7.5) | 14% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security… | |
| Analizada | Crítica (9.8) | 14% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… | |
| Analizada | Crítica (9.8) | 76% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… | |
| Analizada | Crítica (9.9) | 72% | 💥 Exploit | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the… | |
| Analizada | Crítica (9.8) | 76% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… | |
| Analizada | Alta (7.5) | 47% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+11 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information.… | |
| Analizada | Crítica (9.1) | 50% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+11 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information.… | |
| Analizada | Alta (7.5) | 78% | 💥 PoC | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+9 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by… | |
| Modificada | Media (5.5) | 3.3% | — | Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+15 | 19/3/2021 | 17/6/2026 | A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. | |
| Modificada | Media (5.5) | 3.0% | — | Apache PdfboxFedoraproject FedoraOracle Banking Trade Finance Process ManagementOracle Banking Treasury Management+11 | 19/3/2021 | 17/6/2026 | A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. | |
| Modificada | Alta (8.8) | 23% | — | Apache Velocity EngineApache Wss4jDebian LinuxOracle Banking Deposits AND Lines OF Credit Servicing+12 | 10/3/2021 | 17/6/2026 | An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine… | |
| Modificada | Media (5.9) | 19% | — | NettyNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationDebian Linux+4 | 9/3/2021 | 17/6/2026 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is… | |
| Modificada | Media (4.3) | 1.1% | — | ElasticsearchOracle Communications Cloud Native Core Automated Test Suite | 8/3/2021 | 17/6/2026 | A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet… | |
| Modificada | Alta (7.1) | 3.4% | — | Openbsd OpensshFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+5 | 5/3/2021 | 17/6/2026 | ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host. | |
| Modificada | Alta (7) | 9.5% | — | Apache TomcatDebian LinuxOracle Agile Product Lifecycle ManagementOracle Communications Cloud Native Core Policy+8 | 1/3/2021 | 25/8/2026 | The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published… | |
| Modificada | Alta (7.5) | 18% | — | Apache TomcatDebian LinuxOracle Agile Product Lifecycle ManagementOracle Communications Cloud Native Core Policy+8 | 1/3/2021 | 25/8/2026 | When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request. | |
| Modificada | Media (5.5) | 0.89% | — | GNU GlibcNetapp Ontap Select Deploy Administration UtilityNetapp A250 FirmwareNetapp 500f Firmware+10 | 26/2/2021 | 17/6/2026 | The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a… | |
| Modificada | Alta (8.2) | 13% | — | Apache BatikFedoraproject FedoraOracle Agile Engineering Data ManagementOracle Banking Apis+18 | 24/2/2021 | 17/6/2026 | Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. | |
| Modificada | Alta (8.8) | 3.3% | — | Pivotal Software Spring SecurityVmware Spring SecurityOracle Communications Element ManagerOracle Communications Interactive Session Recorder+4 | 23/2/2021 | 17/6/2026 | Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the… |