Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.81% | — | SAP Netweaver Process Integration | 14/4/2021 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30, 7.31, 7.40, 7.50, allows an attacker to access information under certain conditions, which would otherwise be restricted. | |
| Modificada | Media (4.8) | 9.9% | 💥 PoC | Apache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+56 | 13/4/2021 | 7/10/2026 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling… | |
| Modificada | Alta (7.4) | 1.3% | — | Redhat Kubernetes-clientRedhat A-mq OnlineRedhat Build OF QuarkusRedhat Codeready Studio+5 | 16/3/2021 | 17/6/2026 | A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system… | |
| Modificada | Alta (8.8) | 23% | — | Apache Velocity EngineApache Wss4jDebian LinuxOracle Banking Deposits AND Lines OF Credit Servicing+12 | 10/3/2021 | 17/6/2026 | An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine… | |
| Modificada | Alta (8.8) | 52% | — | SAP Manufacturing Integration AND Intelligence | 9/3/2021 | 17/6/2026 | SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forward to server. When this dashboard is opened by users having at least SAP_XMII Developer role,… | |
| Modificada | Media (5.3) | 1.0% | — | Vmware Spring Integration ZIP | 1/3/2021 | 17/6/2026 | Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename… | |
| Modificada | Media (5.3) | 0.96% | — | Mantisbt Source Integration | 18/1/2021 | 17/6/2026 | An issue was discovered in the Source Integration plugin before 2.4.1 for MantisBT. An attacker can gain access to the Summary field of private Issues (either marked as Private, or part of a private Project), if they are attached to an existing Changeset. The information is visible on the view.php page, as well as on… | |
| Analizada | Crítica (9.8) | 96% | ⚠ Explotación activa💥 Exploit | Apache StrutsOracle Business IntelligenceOracle Communications Diameter Intelligence HUBOracle Communications Policy Management+4 | 11/12/2020 | 17/6/2026 | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25. | |
| Modificada | Media (5.5) | 1.0% | — | Apache GroovyNetapp SnapcenterOracle Agile Engineering Data ManagementOracle Agile PLM Mcad Connector+17 | 7/12/2020 | 25/8/2026 | Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods… | |
| Modificada | Alta (7.5) | 17% | — | Fasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationNetapp Service Level Manager+35 | 3/12/2020 | 25/8/2026 | A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity. | |
| Modificada | Alta (7.5) | 11% | — | Apache BatikOracle API GatewayOracle Business IntelligenceOracle Communications Application Session Controller+14 | 12/11/2020 | 17/6/2026 | Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. | |
| Modificada | Media (4.9) | 0.91% | — | SAP Process Integration (pgp Module - Business-to-business ADD ON) | 10/11/2020 | 17/6/2026 | SAP Process Integration (PGP Module - Business-to-Business Add On), version - 1.0, allows an attacker to read PGP Keys under certain conditions in the PGP Module of Business-to-Business Add-On, these keys can then be used to read messages processed by the module leading to Information Disclosure. | |
| Modificada | Media (6.5) | 0.94% | — | Dell EMC Openmanage Integration FOR Microsoft System Center | 8/10/2020 | 17/6/2026 | Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an information disclosure vulnerability. Authenticated low privileged OMIMSCC users may be able to retrieve sensitive information from the logs. | |
| Modificada | Alta (7.5) | 8.0% | — | Apache ANTGradleFedoraproject FedoraOracle Agile Engineering Data Management+33 | 1/10/2020 | 17/6/2026 | As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still… | |
| Modificada | Alta (7.8) | 0.43% | — | Pingidentity Pingid Integration FOR Windows Login | 23/9/2020 | 17/6/2026 | PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe. | |
| Modificada | Media (6.5) | 11% | 💥 PoC | Vmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRMOracle Communications Design Studio+34 | 19/9/2020 | 17/6/2026 | In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter. | |
| Modificada | Alta (8.2) | 0.89% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+16 | 16/9/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted.… | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Pipeline Maven Integration | 16/9/2020 | 17/6/2026 | Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | |
| Modificada | Alta (7.5) | 66% | — | Apache StrutsOracle Communications Policy ManagementOracle Financial Services Data Integration HUBOracle Financial Services Market Risk Measurement AND Management+1 | 14/9/2020 | 17/6/2026 | An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload. | |
| Modificada | Crítica (9.8) | 97% | 💥 Exploit | Apache StrutsOracle Communications Policy ManagementOracle Financial Services Data Integration HUBOracle Financial Services Market Risk Measurement AND Management+1 | 14/9/2020 | 17/6/2026 | Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. | |
| Modificada | Media (6.5) | 0.86% | — | Jenkins Pipeline Maven Integration | 12/8/2020 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows attackers to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 1.1% | — | Jenkins Pipeline Maven Integration | 12/8/2020 | 17/6/2026 | A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.84% | — | Jenkins Pipeline Maven Integration | 12/8/2020 | 17/6/2026 | A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. | |
| Modificada | Crítica (9.8) | 4.4% | — | Vmware Spring IntegrationOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Supply Chain Finance+4 | 31/7/2020 | 17/6/2026 | Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" exploit when provided data contains malicious code for execution… | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Sonargraph Integration | 2/7/2020 | 17/6/2026 | Jenkins Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form validation, resulting in a stored cross-site scripting vulnerability. |