Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.22% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 14/7/2021 | 17/6/2026 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could… | |
| Modificada | Alta (7.5) | 13% | — | Apache Commons CompressOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Enterprise Default Management+30 | 13/7/2021 | 17/6/2026 | When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package. | |
| Modificada | Alta (7.5) | 11% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Apis+23 | 13/7/2021 | 17/6/2026 | When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package. | |
| Modificada | Alta (7.5) | 12% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+20 | 13/7/2021 | 17/6/2026 | When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package. | |
| Modificada | Alta (7.5) | 12% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+22 | 13/7/2021 | 17/6/2026 | When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package. | |
| Modificada | Alta (8.8) | 1.1% | — | Cisco Business Process Automation | 8/7/2021 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper authorization enforcement for specific features and for access to log files that… | |
| Modificada | Alta (8.8) | 1.7% | — | Cisco Business Process Automation | 8/7/2021 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper authorization enforcement for specific features and for access to log files that… | |
| Modificada | Media (4.3) | 0.85% | — | IBM Business Automation WorkflowIBM Business Process Manager | 28/6/2021 | 17/6/2026 | IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779. | |
| Modificada | Crítica (9.1) | 33% | — | Wibu CodemeterSiemens PSS CapeSiemens Sicam 230 FirmwareSiemens Simatic Information Server+6 | 16/6/2021 | 17/6/2026 | A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server. | |
| Modificada | Media (5.5) | 3.1% | — | Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+3 | 12/6/2021 | 17/6/2026 | In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. | |
| Modificada | Media (5.5) | 3.4% | — | Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+8 | 12/6/2021 | 17/6/2026 | In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. | |
| Modificada | Media (6.5) | 0.35% | — | Debian LinuxFedoraproject FedoraIntel Pentium Processors FirmwareIntel Celeron Processors Firmware+3 | 9/6/2021 | 17/6/2026 | Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.5) | 0.35% | — | Intel Brand Verification ToolFedoraproject FedoraIntel Pentium Processors FirmwareIntel Celeron Processors Firmware+3 | 9/6/2021 | 17/6/2026 | Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.3) | 0.27% | — | Intel Processor Diagnostic Tool | 9/6/2021 | 17/6/2026 | Uncontrolled search path element in the Intel(R) Processor Diagnostic Tool before version 4.1.5.37 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.3) | 0.66% | — | Redhat Descision ManagerRedhat JbpmRedhat Process Automation | 1/6/2021 | 17/6/2026 | A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The highest threat from this vulnerability is to confidentiality. | |
| Modificada | Alta (8.8) | 77% | 💥 Exploit | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+13 | 28/5/2021 | 7/10/2026 | XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's… | |
| Modificada | Media (4.9) | 0.85% | — | SAP Netweaver Process Integration | 11/5/2021 | 17/6/2026 | The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not check the file type extension of the file uploaded from local source. An attacker could craft a malicious file and upload it to the application, which could lead to denial of service and impact… | |
| Modificada | Media (4.9) | 0.85% | — | SAP Netweaver Process Integration | 11/5/2021 | 17/6/2026 | The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicious XML which when uploaded and parsed by the application, could lead to Denial-of-service… | |
| Modificada | Media (6.5) | 1.1% | — | IBM Robotic Process Automation With Automation Anywhere | 7/5/2021 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11.0 could allow an attacker on the network to obtain sensitive information or cause a denial of service through username enumeration. IBM X-Force ID: 190992. | |
| Modificada | Alta (8.1) | 0.93% | — | Oracle Concurrent Processing | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Concurrent… | |
| Modificada | Alta (8.1) | 0.93% | — | Oracle Manufacturing Execution System FOR Process Manufacturing | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Process Operations). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle MES for Process… | |
| Modificada | Media (6.5) | 0.79% | — | SAP Netweaver Process Integration | 14/4/2021 | 17/6/2026 | In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Repository JAVA Mappings), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, SAP recommends to refer this note. | |
| Modificada | Media (6.5) | 0.81% | — | SAP Netweaver Process Integration | 14/4/2021 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30, 7.31, 7.40, 7.50, allows an attacker to access information under certain conditions, which would otherwise be restricted. | |
| Modificada | Alta (8.8) | 1.8% | — | Portprocesses Project Portprocesses | 31/3/2021 | 17/6/2026 | This affects the package portprocesses before 1.0.5. If (attacker-controlled) user input is given to the killProcess function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. | |
| Modificada | Media (5.9) | 4.9% | — | NettyDebian LinuxNetapp Oncommand API ServicesNetapp Oncommand Workflow Automation+14 | 30/3/2021 | 17/6/2026 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not… |