Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
942 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.54% | — | SAP Netweaver Application Server Java | 14/7/2021 | 17/6/2026 | When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted. | |
| Modificada | Media (4.9) | 1.6% | — | SAP Netweaver Application Server Java | 14/7/2021 | 17/6/2026 | SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information. | |
| Modificada | Alta (7.5) | 3.2% | — | SAP Netweaver Application Server Java | 14/7/2021 | 17/6/2026 | SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service… | |
| Modificada | Media (5.9) | 0.45% | — | Owasp Enterprise Security API FOR Java | 22/6/2021 | 16/6/2026 | It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks. | |
| Modificada | Media (6.5) | 1.6% | — | SAP Netweaver Application Server FOR Java | 9/6/2021 | 17/6/2026 | SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by… | |
| Modificada | Media (4.9) | 0.61% | — | SAP Netweaver Application Server FOR Java | 9/6/2021 | 17/6/2026 | Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7.11,7.20,7.30,7.31,7.40 and 7.50 allows attackers to access restricted information by entering malicious server name. | |
| Modificada | Media (5.9) | 1.5% | — | Bouncycastle Bc-csharpBouncycastle Bouncy Castle Fips .net APIBouncycastle Fips Java APIBouncycastle THE Bouncy Castle Crypto Package FOR Java | 20/5/2021 | 17/6/2026 | Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic… | |
| Modificada | Crítica (9.8) | 5.7% | — | Oracle Platform Security FOR Java | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform… | |
| Modificada | Media (5.4) | 0.47% | — | SAP Netweaver Application Server Java | 13/4/2021 | 17/6/2026 | SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (XSS) vulnerability and the attacker can read and modify data. However, the attacker does not have… | |
| Modificada | Media (5.3) | 0.64% | — | SAP Netweaver Application Server Java | 13/4/2021 | 17/6/2026 | SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet. | |
| Modificada | Media (4.3) | 0.56% | — | SAP Netweaver Application Server Java | 13/4/2021 | 17/6/2026 | SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled. | |
| Modificada | Media (6.5) | 0.94% | — | SAP Netweaver Application Server Java | 13/4/2021 | 17/6/2026 | An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user. | |
| Analizada | Alta (8.6) | 47% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+13 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed… | |
| Modificada | Alta (7.8) | 62% | — | Microsoft Maven FOR Java | 11/3/2021 | 19/8/2026 | Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability | |
| Modificada | Media (6.1) | 0.69% | — | SAP Netweaver Application Server Java | 10/3/2021 | 17/6/2026 | SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities. | |
| Modificada | Baja (3.3) | 0.63% | — | Datadoghq Datadog-api-client-java | 3/3/2021 | 17/6/2026 | The Java client for the Datadog API before version 1.0.0-beta.9 has a local information disclosure of sensitive information downloaded via the API using the API Client. The Datadog API is executed on a unix-like system with multiple users. The API is used to download a file containing sensitive information. This… | |
| Modificada | Media (6.8) | 0.44% | — | Mongodb Java DriverQuarkus | 25/2/2021 | 17/6/2026 | Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java… | |
| Modificada | Media (6.5) | 1.8% | — | Hubspot Jinjava | 19/2/2021 | 17/6/2026 | Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure. | |
| Modificada | Baja (3.3) | 0.34% | — | Squareup Connect Java Software Development KIT | 3/2/2021 | 17/6/2026 | This affects all versions of package com.squareup:connect. The method prepareDownloadFilecreates creates a temporary file with the permissions bits of -rw-r--r-- on unix-like systems. On unix-like systems, the system temporary directory is shared between users. As such, the contents of the file downloaded by… | |
| Modificada | Alta (8.8) | 3.2% | — | Apache Java Chassis | 25/1/2021 | 17/6/2026 | When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5 | |
| Modificada | Crítica (9.1) | 3.6% | — | Kubernetes Java | 21/1/2021 | 17/6/2026 | Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. | |
| Modificada | Crítica (9.8) | 2.1% | — | Amazon AWS SDK FOR JavasciptAmazon AWS Shared Configuration File Loader | 19/1/2021 | 17/6/2026 | This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the… | |
| Modificada | Alta (7) | 0.40% | — | Apache Html/java API | 11/1/2021 | 17/6/2026 | There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/Java API version 1.7. A similar vulnerability has recently been disclosed in other Java projects and the fix in HTML/Java API version 1.7.1 follows theirs: To avoid local… | |
| Modificada | Alta (8.1) | 7.2% | — | Bouncycastle Bc-javaApache KarafOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+16 | 18/12/2020 | 17/6/2026 | An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different. | |
| Modificada | Alta (7.8) | 3.3% | — | Redhat Language Support FOR Java | 10/12/2020 | 17/6/2026 | Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability |