Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

942 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.3)0.30%—Google Oauth Client Library FOR Java3/5/202217/6/2026
The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An attacker can provide a compromised token with custom payload. The token will pass the validation on the client side. We…
ModificadaCrítica (9.8)3.9%—Alibabagroup One-java-agent1/5/202217/6/2026
All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable files and either invoke them remotely or…
ModificadaMedia (5.3)1.1%—Eclipse Openj9Oracle Java SE27/4/202217/6/2026
In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.
ModificadaMedia (5.3)2.8%—Oracle GraalvmOracle Java SENetapp Active IQ Unified ManagerNetapp Cloud Insights Acquisition Unit+1219/4/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows…
ModificadaBaja (3.7)2.7%—Oracle GraalvmOracle Java SENetapp Active IQ Unified ManagerNetapp Cloud Insights Acquisition Unit+1219/4/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Difficult to exploit vulnerability allows…
ModificadaAlta (7.5)0.37%—Ebics Java Project Ebics Java14/4/202217/6/2026
A vulnerability in the encryption implementation of EBICS messages in the open source librairy ebics-java/ebics-java-client allows an attacker sniffing network traffic to decrypt EBICS payloads. This issue affects: ebics-java/ebics-java-client versions prior to 1.2.
ModificadaAlta (7.5)1.0%—SAP Netweaver Application Server FOR Java12/4/202217/6/2026
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.
ModificadaMedia (5.3)0.77%—SAP Netweaver Application Server Java10/3/202217/6/2026
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
ModificadaAlta (7.8)0.25%—Snowsoftware Snow Inventory Java Scanner16/2/202217/6/2026
A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0
ModificadaAlta (7.5)1.8%—SAP Netweaver Application Server Java9/2/202217/6/2026
Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an attacker could submit multiple HTTP server requests resulting in errors, such that it consumes the memory buffer. This could result in…
ModificadaCrítica (9.8)2.4%—SAP Netweaver Application Server Java9/2/202217/6/2026
In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request which triggers improper shared memory buffer handling. This could allow the malicious payload to be…
ModificadaMedia (5.4)0.50%—Javaquarkbbs Project Javaquarkbbs19/1/202217/6/2026
There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into the background tag management module, the attack statement will be stored in the database, and the next victim will be attacked when he accesses the tag module.
ModificadaMedia (5.5)1.7%—Google-protobufGoogle Protobuf-javaGoogle Protobuf-kotlinOracle Communications Cloud Native Core Console+310/1/202217/6/2026
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend…
ModificadaAlta (7.5)3.1%—Apache Parquet Java20/12/202117/6/2026
Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions.
ModificadaCrítica (9.8)1.9%—Matrix ElementMatrix Javascript SDKMatrix OLMSchildichat+214/12/202117/6/2026
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to…
ModificadaCrítica (9.8)1.0%—Starkbank Ecdsa-java9/11/202117/6/2026
The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
ModificadaAlta (7.1)0.90%—Oracle Java Virtual Machine20/10/202117/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Difficult to exploit vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks…
ModificadaCrítica (9.8)3.0%—Owasp Java Html SanitizerOracle Middleware Common Libraries AND ToolsOracle Primavera Unifier18/10/202117/6/2026
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
ModificadaMedia (6.7)0.47%—Kubernetes Java11/10/202117/6/2026
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.
ModificadaAlta (7.5)7.4%—Apache Santuario XML Security FOR JavaApache CXFApache TomeeDebian Linux+1419/9/202125/8/2026
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a…
ModificadaCrítica (9.8)1.1%—SAP Netweaver Application Server Java14/9/202117/6/2026
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.
ModificadaMedia (5.9)0.66%—Matrix Javascript SDK13/9/202117/6/2026
A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in…
ModificadaAlta (7.8)0.88%—Asyncapi Java-spring-cloud-stream-template11/8/202117/6/2026
@asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker controls the AsyncAPI document. An example is provided in GHSA-xj6r-2jpm-qvxp. There are no mitigations available and all users are advised…
ModificadaMedia (6.1)3.4%—Tiny Java WEB Server Project Tiny Java WEB Server9/8/202117/6/2026
A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS) <=1.115 allows an adversary to inject malicious code on the server's "404 Page not Found" error page
ModificadaMedia (4.3)0.84%—Oracle Java Virtual Machine21/7/202117/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this…