Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

523 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)95%💥 PoCRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss WEB ServerRedhat Enterprise Linux+51/9/201617/6/2026
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated…
ModificadaCrítica (9.8)3.7%💥 PoCRedhat DashbuilderRedhat Jboss BPM SuiteRedhat Jboss Enterprise Brms Platform5/8/201617/6/2026
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.
ModificadaCrítica (9.8)6.8%—Redhat Jboss Operations Network2/8/201617/6/2026
The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.
ModificadaAlta (8.1)56%—Apache Http ServerHP System Management HomepageOracle Communications User Data RepositoryOracle Enterprise Manager OPS Center+1619/7/201617/6/2026
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a…
ModificadaCrítica (9.8)4.7%—Redhat JgroupsRedhat Jboss Enterprise Application Platform30/6/201617/6/2026
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message…
AnalizadaCrítica (9.8)93%⚠ Explotación activa💥 ExploitApache AuroraApache ShiroRedhat FuseRedhat Jboss Middleware Text-only Advisories7/6/201617/6/2026
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
AnalizadaAlta (7.5)8.2%—Redhat Jboss MiddlewareDebian LinuxFedoraproject FedoraXstream17/5/201617/6/2026
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
ModificadaAlta (7.5)7.0%💥 PoCOpensuse LeapDebian LinuxHP Icewall Federation AgentHP Icewall File Manager+1017/5/201617/6/2026
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.
ModificadaAlta (7.5)2.6%—Jboss Enterprise Application Platform6/5/201617/6/2026
The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshake, aka a read-timeout vulnerability.
ModificadaAlta (7.5)16%💥 ExploitRedhat Jboss Wildfly Application Server1/4/201617/6/2026
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) "meaningless"…
ModificadaBaja (3.5)1.8%—Redhat Jboss Enterprise Application Platform16/12/201517/6/2026
Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the server, which allows remote authenticated users with the Monitor, Deployer, or Auditor role to cause a denial of service via unspecified vectors.
ModificadaMedia (5)3.0%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Wildfly Application Server27/10/201517/6/2026
The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.
ModificadaMedia (6.8)1.1%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Wildfly Application Server27/10/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.CR9 allows remote attackers to hijack the authentication of administrators for requests that make arbitrary changes to an…
ModificadaMedia (4.3)1.7%—Redhat Jboss Wildfly Application ServerRedhat Jboss Enterprise Application Platform27/10/201517/6/2026
The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
ModificadaMedia (5.8)1.6%—Redhat Jboss Portal11/8/201517/6/2026
The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.
ModificadaMedia (4.3)1.2%—Redhat Jboss Operations Network11/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in the 404 error page in Red Hat JBoss Operations Network before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModificadaAlta (7.5)2.2%—Redhat Jboss BPM Suite11/8/201517/6/2026
XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red Hat JBoss BPM Suite before 6.1.2 allows remote attackers to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and have other unspecified impact…
ModificadaMedia (4.9)1.5%—Redhat Jboss Enterprise Portal Platform16/7/201517/6/2026
The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted resources, which allows remote attackers to obtain sensitive information via a URL with a modified resource ID.
ModificadaMedia (6)1.5%—Redhat Jboss Fuse8/7/201517/6/2026
Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.
ModificadaMedia (4.3)0.83%—Async-http-client Project Async-http-clientRedhat Jboss Fuse24/6/201517/6/2026
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
ModificadaMedia (4.3)0.99%—Redhat Jboss FuseAsync-http-client Project Async-http-client24/6/201517/6/2026
Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC…
ModificadaAlta (9)2.2%—Redhat Jboss Operations Network24/4/201517/6/2026
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.
ModificadaBaja (2.1)0.37%—Redhat Jboss Enterprise Application Platform21/4/201517/6/2026
The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.
ModificadaMedia (6.4)17%—Canonical Ubuntu LinuxApache BatikRedhat Jboss Enterprise Brms Platform24/3/201517/6/2026
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.
ModificadaBaja (3.6)0.80%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms Platform20/2/201517/6/2026
PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.
Orbitaley — Vulnerabilidades