Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 2.1% | — | Pingidentity Pingid Integration FOR Windows Login | 30/6/2022 | 17/6/2026 | PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login… | |
| Modificada | Media (5.5) | 0.23% | — | Pingidentity Pingid Integration FOR Windows Login | 30/6/2022 | 17/6/2026 | PingID Windows Login prior to 2.8 is vulnerable to a denial of service condition on local machines when combined with using offline security keys as part of authentication. | |
| Modificada | Alta (7.5) | 0.78% | — | Pingidentity Pingid Integration FOR MAC Login | 30/6/2022 | 17/6/2026 | A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass. | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Ns-nd Integration Performance Publisher | 23/6/2022 | 17/6/2026 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (4.8) | 0.60% | — | Facebook-wall-and-social-integration Project Facebook-wall-and-social-integration | 13/6/2022 | 17/6/2026 | The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (5.9) | 1.3% | — | Redhat IntegrationRedhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat Undertow+4 | 24/5/2022 | 17/6/2026 | A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to… | |
| Modificada | Alta (8.1) | 0.45% | — | Pingidentity Pingid Integration FOR Windows Login | 4/5/2022 | 17/6/2026 | Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials. | |
| Modificada | Alta (7.7) | 0.88% | — | Pingidentity Pingone MFA Integration KIT | 2/5/2022 | 17/6/2026 | An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication flow. | |
| Modificada | Media (5.6) | 0.50% | — | Pingidentity Pingid Integration FOR Windows Login | 30/4/2022 | 17/6/2026 | A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass. | |
| Modificada | Media (5.3) | 0.92% | — | IBM Rational Lifecycle Integration Adapter FOR WindchillBender Cc612 FirmwareBender Cc613 FirmwareBender Icc15xx Firmware+1 | 27/4/2022 | 17/6/2026 | In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Modificada | Media (6.5) | 1.8% | — | Jenkins Continuous Integration With Toad Edge | 29/3/2022 | 17/6/2026 | The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Item/Read permission to obtain the contents of arbitrary files on Windows controllers. | |
| Modificada | Media (4.3) | 0.75% | — | Jenkins Continuous Integration With Toad Edge | 29/3/2022 | 17/6/2026 | A missing permission check in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. | |
| Modificada | Media (6.5) | 1.8% | — | Jenkins Continuous Integration With Toad Edge | 29/3/2022 | 17/6/2026 | Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Item/Configure permission to read arbitrary files on the Jenkins controller by specifying an input folder on the Jenkins controller as a parameter to its build steps. | |
| Modificada | Media (5.4) | 0.82% | — | Jenkins Continuous Integration With Toad Edge | 29/3/2022 | 17/6/2026 | Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier does not apply Content-Security-Policy headers to report files it serves, resulting in a stored cross-site scripting (XSS) exploitable by attackers with Item/Configure permission or otherwise able to control report contents. | |
| Modificada | Media (5.4) | 0.67% | — | Jenkins Bitbucket Server Integration | 29/3/2022 | 17/6/2026 | Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers. | |
| Modificada | Media (5.4) | 0.82% | — | Jenkins Bitbucket Server Integration | 29/3/2022 | 17/6/2026 | Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consumers. | |
| Modificada | Alta (7.5) | 0.96% | — | Softing Datafeed OPC SuiteSofting OPC UA C++ Software Development KITSofting Secure Integration Server | 11/3/2022 | 17/6/2026 | An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference. | |
| Modificada | Media (6.5) | 0.83% | — | Softing Datafeed OPC SuiteSofting OPC UA C++ Software Development KITSofting Secure Integration Server | 11/3/2022 | 17/6/2026 | An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition. | |
| Modificada | Crítica (9.8) | 1.2% | — | Unisys Messaging Integration Services | 24/1/2022 | 17/6/2026 | Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not properly validated. | |
| Modificada | Media (6.5) | 12% | — | Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+25 | 24/1/2022 | 25/8/2026 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version… | |
| Modificada | Alta (7.8) | 0.24% | — | Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System | 19/1/2022 | 17/6/2026 | The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protection and make unauthorized changes to… | |
| Modificada | Alta (7.1) | 0.14% | — | Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System | 19/1/2022 | 17/6/2026 | Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this vulnerability to decrypt and modify network… | |
| Modificada | Alta (7.5) | 1.6% | — | Oracle Peoplesoft Enterprise CS SA Integration Pack | 19/1/2022 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CS SA Integration Pack product of Oracle PeopleSoft (component: Snapshot Integration). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS SA… | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… |