Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
942 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.97% | — | Stleary Json-javaHutool | 13/12/2022 | 17/6/2026 | A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. | |
| Modificada | Alta (7.5) | 1.2% | — | HutoolStleary Json-java | 13/12/2022 | 17/6/2026 | A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. | |
| Modificada | Media (6.1) | 0.45% | — | SAP Netweaver Application Server Java | 12/12/2022 | 17/6/2026 | Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a script into a web request header. On successful exploitation, an attacker can view or modify information causing a limited impact on the confidentiality and integrity of… | |
| Modificada | Alta (7.5) | 0.71% | — | Google Protobuf-javaGoogle Protobuf-javalite | 12/12/2022 | 17/6/2026 | A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to… | |
| Modificada | Alta (7.5) | 0.95% | — | Google Protobuf-javaGoogle Protobuf-javalite | 12/12/2022 | 17/6/2026 | A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted… | |
| Modificada | Alta (7.8) | 0.42% | — | Nttdata Terasoluna Global FrameworkNttdata Terasoluna Server Framework FOR Java (rich) | 5/12/2022 | 17/6/2026 | TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0.5.1 are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spring Framework which contains the vulnerability.The vulnerability is caused by an improper input… | |
| Modificada | Media (5.5) | 0.43% | — | Bouncycastle Fips Java API | 21/11/2022 | 17/6/2026 | An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in use by the module, resulting in errors or… | |
| Modificada | Media (4.3) | 0.50% | — | Oracle Java Virtual Machine | 18/10/2022 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability… | |
| Modificada | Alta (7.5) | 1.1% | — | Google-protobufGoogle Protobuf-javaGoogle Protobuf-javaliteGoogle Protobuf-kotlin+2 | 12/10/2022 | 17/6/2026 | A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable… | |
| Modificada | Alta (8.1) | 1.9% | — | Amazon WEB Services Redshift Java Database Connectivity Driver | 29/9/2022 | 17/6/2026 | In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name. | |
| Modificada | Alta (7.5) | 1.2% | — | Matrix Javascript SDK | 29/9/2022 | 17/6/2026 | Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identity in place of one of the users’… | |
| Modificada | Media (5.5) | 0.22% | — | IBM Java SDKSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITRedhat Satellite+4 | 29/9/2022 | 17/6/2026 | IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file. | |
| Modificada | Alta (7.5) | 1.2% | — | Matrix Javascript SDK | 28/9/2022 | 17/6/2026 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker… | |
| Modificada | Alta (7.5) | 1.3% | — | Matrix Javascript SDK | 28/9/2022 | 17/6/2026 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others.… | |
| Modificada | Media (5.3) | 1.4% | — | Matrix Javascript SDK | 28/9/2022 | 17/6/2026 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be… | |
| Modificada | Alta (7.5) | 2.6% | — | Graphql-java Project Graphql-java | 12/9/2022 | 17/6/2026 | graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0 and later, 18.3, and 17.4, and 0.0.0-2022-07-26T05-45-04-226aabd9. | |
| Modificada | Alta (7.5) | 0.83% | — | Pdftk-java Project Pdftk-java | 9/9/2022 | 17/6/2026 | PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java. | |
| Modificada | Alta (7.5) | 1.6% | — | Dogtagpki Network Security Services FOR JavaRedhat Enterprise LinuxDebian Linux | 24/8/2022 | 17/6/2026 | A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service. | |
| Modificada | Alta (7.5) | 1.6% | — | Socket.io-client Java | 2/8/2022 | 17/6/2026 | The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format. | |
| Modificada | Alta (7.5) | 81% | — | Apache Xalan-javaDebian LinuxOracle GraalvmOracle JDK+12 | 19/7/2022 | 17/6/2026 | The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java… | |
| Modificada | Media (6.5) | 1.6% | — | Amazon Aws-sdk-java | 15/7/2022 | 17/6/2026 | The AWS SDK for Java enables Java developers to work with Amazon Web Services. A partial-path traversal issue exists within the `downloadDirectory` method in the AWS S3 TransferManager component of the AWS SDK for Java v1 prior to version 1.12.261. Applications using the SDK control the `destinationDirectory`… | |
| Modificada | Alta (7.5) | 1.0% | — | Javadelight Nashorn Sandbox | 14/6/2022 | 17/6/2026 | An issue was discovered in Delight Nashorn Sandbox 0.2.0. There is an ReDoS vulnerability that can be exploited to launching a denial of service (DoS) attack. | |
| Modificada | Crítica (9.8) | 1.0% | — | Biscuitsec Biscuit-authBiscuitsec Biscuit-goBiscuitsec Biscuit-haskellClever-cloud Biscuit-java | 13/6/2022 | 17/6/2026 | Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow an attacker to create a token with any access level. The version 2 of the… | |
| Modificada | Alta (7.5) | 0.73% | — | Javaez Project Javaez | 24/5/2022 | 17/6/2026 | JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical for non-secure applications, however may be critical in a situation where the highest levels of security are required. This issue ONLY… | |
| Modificada | Alta (7.5) | 2.1% | — | Opcfoundation Ua-java | 20/5/2022 | 17/6/2026 | OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that exhaust available resources. |