Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

576 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.1%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+610/6/202017/6/2026
Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902.
ModificadaAlta (7.5)1.6%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+610/6/202017/6/2026
Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180901.
ModificadaAlta (7.5)2.6%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+610/6/202017/6/2026
Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180900.
ModificadaAlta (7.5)5.1%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+610/6/202017/6/2026
Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of the server to execute arbitrary code on the system with the privileges of root or cause server to crash. IBM X-Force ID: 180814.
ModificadaAlta (7.5)3.4%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+610/6/202017/6/2026
Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute commands in a SOAP API. IBM X-Force ID: 180810.
ModificadaMedia (6.3)1.8%—Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+4614/5/202017/6/2026
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an…
ModificadaCrítica (9.8)3.5%—Pingidentity Pingid SSH Integration13/5/202017/6/2026
Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be potentially exploited into a Remote Code Execution vector on the authenticating endpoint.
ModificadaCrítica (9.8)7.3%—Dom4j Project Dom4jOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Banking Platform+341/5/202025/8/2026
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
ModificadaMedia (6.1)99%💥 ExploitJqueryDrupalDebian LinuxFedoraproject Fedora+6629/4/202017/6/2026
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
ModificadaBaja (3.7)8.1%💥 PoCApache Log4jOracle Communications Application Session ControllerOracle Communications Billing AND Revenue ManagementOracle Communications Eagle FTP Table Base Retrieval+4227/4/202017/6/2026
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
ModificadaMedia (5.4)0.67%—IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+1617/4/202017/6/2026
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308.
ModificadaMedia (6.1)0.89%—IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+1617/4/202017/6/2026
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170880.
ModificadaMedia (5.4)0.78%—IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+1517/4/202017/6/2026
IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.
ModificadaMedia (4.3)0.36%—SAP Cloud Platform Integration10/3/202017/6/2026
SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.
ModificadaMedia (5.4)0.56%—IBM Control DeskIBM Maximo AnywhereIBM Maximo FOR AviationIBM Maximo FOR Life Sciences+619/2/202017/6/2026
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162886.
ModificadaMedia (6.1)1.1%—Mantisbt Source Integration13/2/202017/6/2026
A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2.3.1 for MantisBT. The repo_delete.php Delete Repository page allows execution of arbitrary code via a repo name (if CSP settings permit it). This is related to CVE-2018-16362.
ModificadaMedia (5.3)2.4%—Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications BRM - Elastic Charging EngineOracle Communications Diameter Signaling Router+2317/1/202017/6/2026
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and…
ModificadaAlta (7.5)89%💥 PoCVmware Spring FrameworkOracle Application Testing SuiteOracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Policy+2917/1/202017/6/2026
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
ModificadaMedia (6.1)0.76%—SAP Process Integration14/1/202017/6/2026
PI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
ModificadaCrítica (9.8)4.0%—Adobe Stock API IntegrationPrestashop5/12/201917/6/2026
reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.
ModificadaCrítica (9.8)4.0%—Adobe Stock API IntegrationPrestashop5/12/201917/6/2026
reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaCrítica (9.8)0.77%—Europa Eidas-node Integration Package30/10/201917/6/2026
European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected.
ModificadaCrítica (9.8)0.77%—Europa Eidas-node Integration Package30/10/201917/6/2026
European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate.
ModificadaMedia (5.4)0.67%—IBM Maximo Asset ManagementIBM Maximo FOR AviationIBM Maximo FOR Life SciencesIBM Maximo FOR Nuclear Power+524/10/201917/6/2026
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.
Orbitaley — Vulnerabilidades