Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

576 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)2.1%—Pingidentity Pingid Integration FOR Windows Login30/6/202217/6/2026
PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login…
ModificadaMedia (5.5)0.23%—Pingidentity Pingid Integration FOR Windows Login30/6/202217/6/2026
PingID Windows Login prior to 2.8 is vulnerable to a denial of service condition on local machines when combined with using offline security keys as part of authentication.
ModificadaAlta (7.5)0.78%—Pingidentity Pingid Integration FOR MAC Login30/6/202217/6/2026
A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
ModificadaMedia (5.4)0.64%—Jenkins Ns-nd Integration Performance Publisher23/6/202217/6/2026
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaMedia (4.8)0.60%—Facebook-wall-and-social-integration Project Facebook-wall-and-social-integration13/6/202217/6/2026
The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (5.9)1.3%—Redhat IntegrationRedhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat Undertow+424/5/202217/6/2026
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to…
ModificadaAlta (8.1)0.45%—Pingidentity Pingid Integration FOR Windows Login4/5/202217/6/2026
Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials.
ModificadaAlta (7.7)0.88%—Pingidentity Pingone MFA Integration KIT2/5/202217/6/2026
An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication flow.
ModificadaMedia (5.6)0.50%—Pingidentity Pingid Integration FOR Windows Login30/4/202217/6/2026
A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
ModificadaMedia (5.3)0.92%—IBM Rational Lifecycle Integration Adapter FOR WindchillBender Cc612 FirmwareBender Cc613 FirmwareBender Icc15xx Firmware+127/4/202217/6/2026
In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+341/4/202217/6/2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to…
ModificadaMedia (6.5)1.8%—Jenkins Continuous Integration With Toad Edge29/3/202217/6/2026
The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Item/Read permission to obtain the contents of arbitrary files on Windows controllers.
ModificadaMedia (4.3)0.75%—Jenkins Continuous Integration With Toad Edge29/3/202217/6/2026
A missing permission check in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
ModificadaMedia (6.5)1.8%—Jenkins Continuous Integration With Toad Edge29/3/202217/6/2026
Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Item/Configure permission to read arbitrary files on the Jenkins controller by specifying an input folder on the Jenkins controller as a parameter to its build steps.
ModificadaMedia (5.4)0.82%—Jenkins Continuous Integration With Toad Edge29/3/202217/6/2026
Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier does not apply Content-Security-Policy headers to report files it serves, resulting in a stored cross-site scripting (XSS) exploitable by attackers with Item/Configure permission or otherwise able to control report contents.
ModificadaMedia (5.4)0.67%—Jenkins Bitbucket Server Integration29/3/202217/6/2026
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.
ModificadaMedia (5.4)0.82%—Jenkins Bitbucket Server Integration29/3/202217/6/2026
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consumers.
ModificadaAlta (7.5)0.96%—Softing Datafeed OPC SuiteSofting OPC UA C++ Software Development KITSofting Secure Integration Server11/3/202217/6/2026
An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference.
ModificadaMedia (6.5)0.83%—Softing Datafeed OPC SuiteSofting OPC UA C++ Software Development KITSofting Secure Integration Server11/3/202217/6/2026
An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition.
ModificadaCrítica (9.8)1.2%—Unisys Messaging Integration Services24/1/202217/6/2026
Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not properly validated.
ModificadaMedia (6.5)12%—Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+2524/1/202225/8/2026
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version…
ModificadaAlta (7.8)0.24%—Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System19/1/202217/6/2026
The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protection and make unauthorized changes to…
ModificadaAlta (7.1)0.14%—Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System19/1/202217/6/2026
Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this vulnerability to decrypt and modify network…
ModificadaAlta (7.5)1.6%—Oracle Peoplesoft Enterprise CS SA Integration Pack19/1/202217/6/2026
Vulnerability in the PeopleSoft Enterprise CS SA Integration Pack product of Oracle PeopleSoft (component: Snapshot Integration). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS SA…
ModificadaMedia (5.9)100%💥 PoCApache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+11218/12/202125/8/2026
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j…
Orbitaley — Vulnerabilidades