Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
942 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Opcfoundation UA Java LegacyProsysopc UA HistorianProsysopc UA Modbus ServerProsysopc UA Simulation Server | 15/5/2023 | 17/6/2026 | The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications. | |
| Modificada | Crítica (9.1) | 0.62% | — | SAP Netweaver Application Server FOR Java | 9/5/2023 | 17/6/2026 | In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and directory API to instantiate an object which has methods which can be called without further authorization and authentication. A… | |
| Modificada | Media (6.1) | 0.36% | — | Qbian61 Forum-java Project Qbian61 Forum-java | 1/5/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Qbian61 forum-java, allows attackers to inject arbitrary web script or HTML via editing the article content in the "article editor" page. | |
| Modificada | Alta (7.5) | 0.60% | — | IBM Infosphere Information ServerIBM JavaIBM Websphere Application ServerIBM Z/transaction Processing Facility | 29/4/2023 | 17/6/2026 | IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188. | |
| Modificada | Media (5.3) | 0.54% | — | Matrix Javascript SDK | 14/4/2023 | 17/6/2026 | matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An attacker present in a room where an MSC3401 group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. To affected matrix-js-sdk users, the attacker will not appear to be… | |
| Modificada | Media (5.3) | 0.45% | — | SAP Netweaver AS Java FOR Deploy Service | 11/4/2023 | 17/6/2026 | SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity enabling an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but… | |
| Modificada | Alta (7.2) | 0.61% | — | Javadelight Nashorn Sandbox | 10/4/2023 | 17/6/2026 | delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process. | |
| Modificada | Alta (8.2) | 1.2% | — | Matrix Javascript SDK | 28/3/2023 | 17/6/2026 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the… | |
| Modificada | Media (5.3) | 0.94% | — | Matrix Javascript SDK | 28/3/2023 | 17/6/2026 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the… | |
| Modificada | Alta (7.5) | 1.1% | — | Graphql-java | 27/3/2023 | 17/6/2026 | In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0-2023-03-20T01-49-44-80e3135. | |
| Modificada | Media (5.4) | 0.52% | — | Crmeb Java | 23/3/2023 | 17/6/2026 | A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been rated as problematic. This issue affects the function save of the file /api/admin/store/product/save. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.8) | 0.63% | — | Crmeb Java | 23/3/2023 | 17/6/2026 | A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been declared as critical. This vulnerability affects the function getAdminList of the file /api/admin/store/product/list. The manipulation of the argument cateId leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 0.26% | — | Piwebsolution CSS JS Manager, Async Javascript, Defer Render Blocking CSS Supports Woocommerce | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions. | |
| Modificada | Media (5.3) | 0.45% | — | SAP Netweaver Application Server FOR Java | 14/3/2023 | 17/6/2026 | SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and… | |
| Modificada | Media (5.3) | 0.48% | — | SAP Netweaver Application Server FOR Java | 14/3/2023 | 17/6/2026 | Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity | |
| Modificada | Media (5.3) | 0.58% | — | SAP Netweaver Application Server Java | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an unassigned user can read non-sensitive… | |
| Modificada | Alta (8.6) | 0.54% | — | SAP Netweaver Application Server FOR Java | 14/3/2023 | 17/6/2026 | Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and services across systems. On a… | |
| Modificada | Alta (7.2) | 0.76% | — | Crmeb Java | 7/3/2023 | 17/6/2026 | CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list. | |
| Modificada | Crítica (9.8) | 0.97% | — | Forgerock Java Policy Agents | 28/2/2023 | 17/6/2026 | Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1 | |
| Modificada | Crítica (9.8) | 1.2% | — | Java-xmlbuilder Project Java-xmlbuilder | 19/2/2023 | 17/6/2026 | A vulnerability was found in java-xmlbuilder up to 1.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. Upgrading to version 1.2 is able to address this issue. The name of the patch is… | |
| Modificada | Crítica (9.8) | 1.6% | — | Javaweb Blog Project Javaweb Blog | 26/1/2023 | 17/6/2026 | An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile. | |
| Modificada | Media (5.4) | 0.39% | — | Javaweb Blog Project Javaweb Blog | 23/1/2023 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability found in Rawchen blog-ssm v1.0 allows attackers to execute arbitrary code via the 'notifyInfo' parameter. | |
| Modificada | Media (4.3) | 0.56% | — | Oracle Java Virtual Machine | 18/1/2023 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability… | |
| Modificada | Media (5.5) | 0.24% | — | Java-merge-sort Project Java-merge-sort | 12/1/2023 | 17/6/2026 | Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents. | |
| Modificada | Crítica (9.8) | 16% | — | SAP Netweaver Application Server FOR Java | 10/1/2023 | 17/6/2026 | An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could… |