Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

506 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.4%—Broadcom CA API Developer Portal15/4/202017/6/2026
CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
ModificadaMedia (6.1)1.3%—Broadcom CA API Developer Portal15/4/202017/6/2026
CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.
ModificadaAlta (7.5)3.2%—Broadcom CA API Developer Portal15/4/202017/6/2026
CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-Origin Resource Sharing flaw and access sensitive information.
ModificadaAlta (8.1)1.9%—Broadcom CA API Developer Portal15/4/202017/6/2026
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view and edit user data.
ModificadaAlta (7.5)1.1%—Sync Oxygen XML AuthorSync Oxygen XML DeveloperSync Oxygen XML Editor16/3/202017/6/2026
Oxygen XML Editor 21.1.1 allows XXE to read any file.
ModificadaMedia (6.1)1.00%—Oracle Reports Developer15/1/202017/6/2026
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports…
ModificadaMedia (6.1)1.0%—Oracle Reports Developer15/1/202017/6/2026
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports…
ModificadaAlta (7.5)4.7%💥 PoCGolang GODebian LinuxFedoraproject FedoraRedhat Developer Tools+724/10/201917/6/2026
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
ModificadaAlta (8.8)2.0%—XML Language Server Project XML Server ProjectEclipse Wild WEB DeveloperTheia XML Extension Project Theia XML Extension23/10/201917/6/2026
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connection initiation that can lead to NetNTLM challenge/response capture for password…
ModificadaMedia (6.5)2.8%—XML Language Server Project XML Server ProjectEclipse Wild WEB DeveloperTheia XML Extension Project Theia XML Extension23/10/201917/6/2026
XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote attacker to write to arbitrary files via Directory Traversal.
ModificadaMedia (5.5)1.00%—Apache POIOracle Application Testing SuiteOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+2323/10/201917/6/2026
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
ModificadaBaja (2.4)0.88%—Oracle Application Development FrameworkOracle JdeveloperOracle Hyperion Financial ManagementOracle Peoplesoft Enterprise SCM Purchasing16/10/201917/6/2026
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: OAM). Supported versions that are affected are 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle JDeveloper…
ModificadaMedia (6.1)0.78%—Microfocus Enterprise DeveloperMicrofocus Enterprise Server2/10/201917/6/2026
Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, version 4.0 Patch Update 12, and version 5.0 Patch Update 2. The vulnerability could be exploited to redirect a user to a malicious page or forge certain types of web requests.
ModificadaAlta (7.5)5.3%—Golang GODebian LinuxOpensuse LeapFedoraproject Fedora+530/9/201917/6/2026
Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
ModificadaAlta (7.5)2.0%—Wpexpertdeveloper WP Private Content Plus30/8/201917/6/2026
The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_page and other save_ functions.
ModificadaAlta (7.5)16%—Apache Commons CompressFedoraproject FedoraOracle Banking PaymentsOracle Banking Platform+1530/8/201917/6/2026
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
ModificadaAlta (7.5)83%—Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+2413/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can…
ModificadaAlta (8.8)0.69%—Wpdeveloper Twitter Cards Meta12/8/201917/6/2026
The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.
ModificadaMedia (6.1)0.92%—Wpdeveloper Twitter Cards Meta12/8/201917/6/2026
The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS.
ModificadaAlta (7.5)2.7%—Linux KernelRedhat Developer ToolsRedhat MRG RealtimeRedhat Enterprise Linux+1630/7/201917/6/2026
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any…
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaMedia (6.1)2.2%—Golang GODebian LinuxFedoraproject FedoraRedhat Developer Tools+113/3/201917/6/2026
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
ModificadaMedia (6.1)6.5%💥 ExploitOracle Reports Developer16/1/201917/6/2026
Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Valid Session). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks…
ModificadaCrítica (10)10%—Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Communications Billing AND Revenue Management+82/1/201917/6/2026
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
ModificadaCrítica (9.8)7.5%—Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Communications Billing AND Revenue Management+82/1/201917/6/2026
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.