Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modificada | Media (5.5) | 2.6% | — | Apache ANTOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Trade Finance+32 | 14/7/2021 | 25/8/2026 | When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR… | |
| Modificada | Media (4.8) | 9.9% | 💥 PoC | Apache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+56 | 13/4/2021 | 25/8/2026 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling… | |
| Modificada | Alta (8.2) | 13% | — | Apache BatikFedoraproject FedoraOracle Agile Engineering Data ManagementOracle Banking Apis+18 | 24/2/2021 | 17/6/2026 | Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. | |
| Modificada | Baja (2.4) | 1.3% | — | Oracle Agile Engineering Data ManagementOracle Hyperion Infrastructure TechnologyOracle Siebel UI FrameworkOracle Weblogic Server | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Media (5.5) | 1.0% | — | Apache GroovyNetapp SnapcenterOracle Agile Engineering Data ManagementOracle Agile PLM Mcad Connector+17 | 7/12/2020 | 25/8/2026 | Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods… | |
| Modificada | Alta (7.5) | 8.0% | — | Apache ANTGradleFedoraproject FedoraOracle Agile Engineering Data Management+33 | 1/10/2020 | 17/6/2026 | As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still… | |
| Modificada | Alta (7.5) | 87% | 💥 PoC | Apache TomcatDebian LinuxNetapp Oncommand System ManagerOpensuse Leap+14 | 14/7/2020 | 25/8/2026 | The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service. | |
| Modificada | Alta (7.5) | 64% | — | Apache TomcatDebian LinuxNetapp Oncommand System ManagerOpensuse Leap+10 | 14/7/2020 | 25/8/2026 | An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service. | |
| Modificada | Alta (7) | 56% | 💥 Exploit | Apache TomcatDebian LinuxOpensuse LeapFedoraproject Fedora+22 | 20/5/2020 | 25/8/2026 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is… | |
| Modificada | Media (6.3) | 1.8% | — | Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+46 | 14/5/2020 | 17/6/2026 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Apache GeodeApache TomcatFedoraproject FedoraOracle Agile Engineering Data Management+17 | 24/2/2020 | 25/8/2026 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising.… | |
| Modificada | Media (4.8) | 9.4% | — | Apache TomcatDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+16 | 24/2/2020 | 17/6/2026 | In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly… | |
| Modificada | Media (4.8) | 8.9% | — | Apache TomcatApache TomeeOpensuse LeapNetapp Data Availability Services+12 | 24/2/2020 | 25/8/2026 | The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy… | |
| Modificada | Alta (7.5) | 11% | — | Apache TomcatDebian LinuxOpensuse LeapCanonical Ubuntu Linux+7 | 23/12/2019 | 17/6/2026 | When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been… | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (7.5) | 92% | 💥 Exploit | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+33 | 1/5/2019 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version… | |
| Modificada | Media (6.1) | 11% | 💥 PoC | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+34 | 2/8/2018 | 17/6/2026 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. | |
| Modificada | Media (4.8) | 0.90% | — | Oracle Agile Engineering Data Management | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Engineering Data Management component of Oracle Supply Chain Products Suite (subcomponent: Web Services Security). Supported versions that are affected are 6.1.3.0 and 6.2.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | OpensslOracle Agile Engineering Data ManagementOracle Communications Application Session ControllerOracle Communications Eagle LNP Application Processor+3 | 4/5/2017 | 17/6/2026 | In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack. | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa | Apache TomcatCanonical Ubuntu LinuxNetapp 7-mode Transition ToolNetapp Oncommand Insight+15 | 6/4/2017 | 25/8/2026 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427… | |
| Modificada | Alta (8.1) | 1.9% | — | Oracle Agile Engineering Data Management | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to webfileservices. | |
| Modificada | Crítica (9.8) | 5.5% | — | Oracle Agile Engineering Data Management | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Install. | |
| Modificada | Baja (3.1) | 0.80% | — | Oracle Agile Engineering Data Management | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect availability via vectors related to Engineering Communication Interface. | |
| Modificada | Baja (1.5) | 0.33% | — | Oracle Agile Engineering Data Management | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows local users to affect confidentiality via unknown vectors related to Install. |