Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

583 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)5.4%—SqliteSiemens Sinec Infrastructure Network ServicesTenable.scOracle Mysql Workbench+29/12/201917/6/2026
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
ModificadaAlta (7.5)8.0%—SqliteOracle Mysql WorkbenchSiemens Sinec Infrastructure Network ServicesApache Guacamole+29/12/201917/6/2026
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
ModificadaMedia (5.5)0.57%—SqliteNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityOracle Mysql Workbench+29/12/201917/6/2026
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.
ModificadaMedia (6.5)1.3%—Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication6/12/201917/6/2026
Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.
ModificadaCrítica (9.8)4.3%—SqliteNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityOracle Mysql Workbench+15/12/201917/6/2026
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact.
ModificadaMedia (6.5)0.99%—Octopus Deploy28/11/201917/6/2026
In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input validation and causes an application level denial of service condition. (The fix for this was also backported to LTS 2019.9.8 and LTS 2019.6.14.)
ModificadaMedia (5.3)0.42%—Octopus Deploy28/11/201917/6/2026
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.)
ModificadaAlta (7.5)1.3%—Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication26/11/201917/6/2026
Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well.
ModificadaCrítica (9.8)2.3%—Netapp Ontap Select Deploy Administration Utility21/11/201917/6/2026
ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and use a privileged user account.
ModificadaAlta (7.2)1.3%—Netapp Ontap Select Deploy Administration Utility21/11/201917/6/2026
All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully exploited could allow an administrative user to escalate their privileges.
ModificadaCrítica (9.8)2.8%—Redhat EdeployRedhat Jboss Enterprise WEB Server21/11/201917/6/2026
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
ModificadaAlta (8.6)1.5%—Cloudfoundry Cf-deploymentCloudfoundry Routing-release19/11/201917/6/2026
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.
ModificadaMedia (4.3)0.69%—Octopus Deploy18/11/201917/6/2026
In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underlying operating system details.
ModificadaAlta (8.8)1.5%—Cloudfoundry Cf-deploymentPivotal Software Cloud Foundry SMB Volume23/10/201917/6/2026
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.
ModificadaMedia (4.3)1.1%—Cloudfoundry Cf-deploymentPivotal Software Cloud Foundry UAA23/10/201917/6/2026
Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users of the UAA.
ModificadaMedia (4.3)0.79%—Jenkins Deploy Weblogic23/10/201917/6/2026
A missing permission check in Jenkins Deploy WebLogic Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an attacker-specified path exists on the Jenkins master file system.
ModificadaAlta (8.8)0.77%—Jenkins Deploy Weblogic23/10/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an attacker-specified path exists on the Jenkins master file system.
ModificadaAlta (8.1)3.8%💥 PoCLibssh2Fedoraproject FedoraOpensuse LeapDebian Linux+621/10/201917/6/2026
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service…
ModificadaMedia (4.3)0.66%—Jenkins CRX Content Package Deployer16/10/201917/6/2026
A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier in various 'doFillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
ModificadaMedia (6.5)1.0%—Jenkins CRX Content Package Deployer16/10/201917/6/2026
A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaAlta (8.8)0.84%—Jenkins CRX Content Package Deployer16/10/201917/6/2026
A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaCrítica (9.8)5.4%—Fasterxml Jackson-databindDebian LinuxRedhat Jboss Enterprise Application PlatformOracle Banking Platform+1812/10/201917/6/2026
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide…
ModificadaCrítica (9.8)5.7%—Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraRedhat Jboss Enterprise Application Platform+241/10/201917/6/2026
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service…
ModificadaCrítica (9.8)4.9%—Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraRedhat Jboss Enterprise Application Platform+221/10/20197/10/2026
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint…
ModificadaCrítica (9.8)0.84%—Netapp Ontap Select Deploy Administration Utility24/9/201917/6/2026
ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.
Orbitaley — Vulnerabilidades