Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 319 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

942 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)3.8%—Microsoft Azure SDK FOR Java10/12/202017/6/2026
Azure SDK for Java Security Feature Bypass Vulnerability
ModificadaCrítica (10)4.8%—SAP Netweaver Application Server Java9/12/202017/6/2026
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment dedicated for the internal cluster communication. As result, an…
ModificadaMedia (6.5)1.2%—SAP Netweaver Application Server Java9/12/202017/6/2026
Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload.
ModificadaMedia (4.5)0.17%—SAP Netweaver Application Server Java9/12/202017/6/2026
SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encrypted. This enables an attacker who has administrator access to the SAP NetWeaver…
ModificadaAlta (8.8)12%—Artworks Gallery IN Php, Css, Javascript, AND Mysql Project Artworks Gallery IN Php, Css, Javascript, AND Mysql17/11/202017/6/2026
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
ModificadaAlta (8.8)12%—Artworks Gallery IN Php, Css, Javascript, AND Mysql Project Artworks Gallery IN Php, Css, Javascript, AND Mysql17/11/202017/6/2026
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
ModificadaAlta (7.2)3.9%—SAP Netweaver Application Server Java10/11/202017/6/2026
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate mechanism to execute OS…
ModificadaMedia (5.3)0.92%—Bouncycastle Fips Java APIBouncycastle Legion-of-the-bouncy-castle2/11/202017/6/2026
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short…
ModificadaBaja (3.1)0.75%—Oracle Java Virtual Machine21/10/202017/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Procedure privilege with network access via multiple protocols to compromise Java VM.…
AnalizadaMedia (5.3)0.46%—Google Tink Java19/10/202017/6/2026
A mis-handling of invalid unicode characters in the Java implementation of Tink versions prior to 1.5 allows an attacker to change the ID part of a ciphertext, which result in the creation of a second ciphertext that can decrypt to the same plaintext. This can be a problem with encrypting deterministic AEAD with a…
ModificadaMedia (6.1)1.1%—SAP Netweaver Application Server Java15/10/202017/6/2026
SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation. The attacker could execute phishing attacks to steal credentials of the victim or to redirect…
ModificadaMedia (6.1)0.91%—SAP Netweaver Application Server Java15/10/202017/6/2026
SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScript blocks in any web page or URL with different symbols which are otherwise not allowed. On successful exploitation an attacker can steal authentication information of…
ModificadaMedia (6.5)0.72%—SAP Netweaver Application Server Java9/9/202017/6/2026
SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an authenticated User with special roles to store malicious content, that when accessed by a victim, can perform malicious actions by executing JavaScript, leading to…
ModificadaCrítica (9.8)2.6%—Noise-java Project Noise-java4/9/202017/6/2026
An issue was discovered in Noise-Java through 2020-08-27. AESGCMOnCtrCipherState.encryptWithAd() allows out-of-bounds access.
ModificadaCrítica (9.8)2.6%—Noise-java Project Noise-java4/9/202017/6/2026
An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds access.
ModificadaCrítica (9.8)2.6%—Noise-java Project Noise-java4/9/202017/6/2026
An issue was discovered in Noise-Java through 2020-08-27. ChaChaPolyCipherState.encryptWithAd() allows out-of-bounds access.
ModificadaAlta (7.5)1.8%—SAP Netweaver Application Server Java12/8/202017/6/2026
SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authentication checks for a web service allowing the attacker to send several payloads and leading to complete denial of service.
ModificadaMedia (6.1)1.4%—TC Custom Javascript Project TC Custom Javascript21/7/202017/6/2026
A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows unauthenticated remote attackers to inject arbitrary JavaScript via the tccj-content parameter. This is displayed in the page footer of every front-end page and executed in the browser of visitors.
AnalizadaCrítica (10)95%⚠ Explotación activaSAP Netweaver Application Server Java14/7/202017/6/2026
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative…
ModificadaMedia (5.3)28%—SAP Netweaver Application Server Java14/7/202017/6/2026
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.
ModificadaMedia (5.8)1.1%—SAP Netweaver Application Server Java14/7/202017/6/2026
SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send a crafted request from a vulnerable web application. It is usually used to target…
ModificadaCrítica (9.1)1.6%—Google Oauth Client Library FOR Java9/7/202017/6/2026
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able…
ModificadaCrítica (9.8)1.4%—SAP Netweaver Application Server Java10/6/202017/6/2026
Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not perform any authentication checks for operations that require user identity…
ModificadaAlta (7.5)0.67%—Couchbase Server Java SDK8/6/202017/6/2026
Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that will be accepted by Java SDK's Netty component due to missing hostname verification.
ModificadaAlta (8.1)3.0%—Verizon Serialize-javascript1/6/202017/6/2026
serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".