Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1092 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 8.4% | 💥 PoC | Netapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+41 | 6/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource. | |
| Modificada | Alta (8.1) | 4.1% | — | Netapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+40 | 6/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS. | |
| Analizada | Alta (8.1) | 13% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxNetapp Service Level ManagerOracle Agile Product Lifecycle Management+36 | 27/12/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl). | |
| Modificada | Alta (8.1) | 7.2% | 💥 PoC | Bouncycastle Bc-javaApache KarafOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+16 | 18/12/2020 | 17/6/2026 | An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different. | |
| Modificada | Alta (8.1) | 7.8% | — | Fasterxml Jackson-databindNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+22 | 17/12/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource. | |
| Modificada | Alta (8.1) | 6.3% | — | Fasterxml Jackson-databindNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+21 | 17/12/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource. | |
| Modificada | Alta (7.5) | 3.5% | — | P11-kit Project P11-kitDebian LinuxOracle Communications Cloud Native Core Policy | 16/12/2020 | 17/6/2026 | An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient… | |
| Modificada | Alta (7.5) | 4.6% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+13 | 14/12/2020 | 17/6/2026 | curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. | |
| Modificada | Alta (7.5) | 9.8% | — | Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. | |
| Modificada | Baja (3.7) | 3.9% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions. | |
| Modificada | Alta (7.5) | 3.8% | — | Haxx LibcurlSiemens Sinec Infrastructure Network ServicesDebian LinuxOracle Communications Cloud Native Core Policy+1 | 14/12/2020 | 17/6/2026 | Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data. | |
| Analizada | Crítica (9.8) | 96% | ⚠ Explotación activa💥 Exploit | Apache StrutsOracle Business IntelligenceOracle Communications Diameter Intelligence HUBOracle Communications Policy Management+4 | 11/12/2020 | 17/6/2026 | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25. | |
| Modificada | Baja (3.3) | 0.92% | — | Google GuavaQuarkusOracle Commerce Guided SearchOracle Communications Cloud Native Core Network Slice Selection Function+9 | 10/12/2020 | 17/6/2026 | A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable… | |
| Modificada | Media (5.9) | 7.1% | 💥 PoC | OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+40 | 8/12/2020 | 17/6/2026 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both… | |
| Modificada | Media (5.5) | 1.0% | — | Apache GroovyNetapp SnapcenterOracle Agile Engineering Data ManagementOracle Agile PLM Mcad Connector+17 | 7/12/2020 | 25/8/2026 | Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods… | |
| Modificada | Alta (7.5) | 25% | 💥 PoC | Apache TomcatNetapp Element Plug-inNetapp Oncommand System ManagerDebian Linux+8 | 3/12/2020 | 17/6/2026 | While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead… | |
| Modificada | Media (6.1) | 4.0% | — | LxmlRedhat Software CollectionsRedhat Enterprise LinuxDebian Linux+4 | 3/12/2020 | 17/6/2026 | A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code. | |
| Modificada | Alta (7.5) | 17% | — | Fasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationNetapp Service Level Manager+35 | 3/12/2020 | 25/8/2026 | A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity. | |
| Modificada | Media (5.3) | 9.0% | — | Apache HttpclientQuarkusOracle Data IntegratorOracle JD Edwards Enterpriseone Orchestrator+13 | 2/12/2020 | 17/6/2026 | Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. | |
| Modificada | Alta (7.4) | 2.9% | — | Hibernate ORMDebian LinuxQuarkusOracle Communications Cloud Native Core Console+1 | 2/12/2020 | 17/6/2026 | A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly… | |
| Modificada | Media (4.8) | 8.3% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkOracle Blockchain Platform+13 | 28/11/2020 | 17/6/2026 | In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely… | |
| Modificada | Media (4.7) | 0.39% | — | IBM ViosIBM AIXFedoraproject FedoraOracle Communications Cloud Native Core Binding Support Function+2 | 20/11/2020 | 17/6/2026 | IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296. | |
| Analizada | Alta (8.8) | 85% | 💥 Exploit | XstreamDebian LinuxNetapp SnapmanagerApache Activemq+11 | 16/11/2020 | 7/10/2026 | XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The… | |
| Modificada | Alta (7.5) | 11% | — | Apache BatikOracle API GatewayOracle Business IntelligenceOracle Communications Application Session Controller+14 | 12/11/2020 | 17/6/2026 | Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. | |
| Modificada | Media (6.1) | 41% | — | Apache CXFNetapp Snap Creator FrameworkNetapp Vasa Provider FOR Clustered Data OntapOracle Business Intelligence+2 | 12/11/2020 | 17/6/2026 | By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all… |