Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
506 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 64% | — | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+22 | 18/1/2022 | 17/6/2026 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink… | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modificada | Alta (7.5) | 81% | 💥 PoC | Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+42 | 14/12/2021 | 17/6/2026 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in… | |
| Modificada | Media (5.4) | 0.62% | — | Wpdeveloper Betterlinks | 23/11/2021 | 17/6/2026 | The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV. | |
| Modificada | Media (4.3) | 0.67% | — | Wpdeveloper Countdown Block | 27/9/2021 | 17/6/2026 | The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users. | |
| Modificada | Crítica (9.8) | 2.0% | — | Edgegallery Developer-be | 30/8/2021 | 17/6/2026 | An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability that can allow attackers to execute system command through uploading the malicious constructed YAML file. | |
| Modificada | Alta (8.8) | 2.6% | 💥 PoC | Wpdeveloper Simple 301 Redirects | 14/6/2021 | 17/6/2026 | In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites. | |
| Modificada | Media (4.3) | 0.72% | — | Wpdeveloper Simple 301 Redirects | 14/6/2021 | 17/6/2026 | In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for… | |
| Modificada | Alta (8.8) | 1.5% | — | Wpdeveloper Simple 301 Redirects | 14/6/2021 | 17/6/2026 | A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites. | |
| Modificada | Alta (8.8) | 1.1% | — | Wpdeveloper Simple 301 Redirects | 14/6/2021 | 17/6/2026 | The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects. | |
| Modificada | Alta (8.8) | 1.2% | — | Wpdeveloper Simple 301 Redirects | 14/6/2021 | 17/6/2026 | The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects. | |
| Modificada | Media (5.4) | 0.59% | — | Wpdeveloper Essential Addons FOR Elementor | 5/5/2021 | 17/6/2026 | The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, both via a similar method. | |
| Modificada | Crítica (9.8) | 6.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all… | |
| Modificada | Crítica (9.8) | 3.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3… | |
| Modificada | Media (5.3) | 9.0% | — | Apache HttpclientQuarkusOracle Data IntegratorOracle JD Edwards Enterpriseone Orchestrator+13 | 2/12/2020 | 17/6/2026 | Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. | |
| Modificada | Baja (2.8) | 0.41% | — | Oracle SQL Developer | 21/10/2020 | 17/6/2026 | Vulnerability in the SQL Developer Install component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Client Computer User Account privilege with logon to the infrastructure where SQL… | |
| Modificada | Media (5.4) | 0.51% | — | Microfocus Enterprise DeveloperMicrofocus Enterprise Server | 18/5/2020 | 17/6/2026 | Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed… | |
| Modificada | Crítica (9.8) | 7.3% | — | Dom4j Project Dom4jOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Banking Platform+34 | 1/5/2020 | 25/8/2026 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j. | |
| Modificada | Media (6.1) | 99% | 💥 Exploit | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Alta (8.8) | 0.86% | — | Microfocus Enterprise DeveloperMicrofocus Enterprise Server | 17/4/2020 | 17/6/2026 | Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user account running the Micro Focus… | |
| Modificada | Media (6.5) | 1.4% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view restricted sensitive information. | |
| Modificada | Media (4.3) | 0.92% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a restricted user administration action. | |
| Modificada | Crítica (9.8) | 2.4% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization. | |
| Modificada | Alta (8.8) | 3.0% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows malicious users to elevate privileges. | |
| Modificada | Media (6.1) | 1.6% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks. |