Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 8.4% | — | Netapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+41 | 6/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource. | |
| Modificada | Alta (8.1) | 4.1% | — | Netapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+40 | 6/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS. | |
| Analizada | Alta (8.1) | 13% | — | Fasterxml Jackson-databindDebian LinuxNetapp Service Level ManagerOracle Agile Product Lifecycle Management+36 | 27/12/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl). | |
| Modificada | Alta (8.1) | 7.8% | — | Fasterxml Jackson-databindNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+22 | 17/12/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource. | |
| Modificada | Alta (8.1) | 6.3% | — | Fasterxml Jackson-databindNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+21 | 17/12/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource. | |
| Modificada | Alta (8.1) | 7.3% | — | Fasterxml Jackson-databindOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Autovue FOR Agile Product Lifecycle Management+22 | 17/9/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. | |
| Modificada | Alta (8.1) | 7.6% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+21 | 25/8/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP). | |
| Modificada | Crítica (9.8) | 17% | — | Apache Log4netFedoraproject FedoraOracle Application Testing SuiteOracle Hospitality Opera 5+3 | 11/5/2020 | 17/6/2026 | Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files. | |
| Modificada | Crítica (9.8) | 7.3% | — | Dom4j Project Dom4jOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Banking Platform+34 | 1/5/2020 | 25/8/2026 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j. | |
| Modificada | Media (6.1) | 99% | — | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Analizada | Media (6.1) | 85% | ⚠ Explotación activa | JqueryDebian LinuxFedoraproject FedoraDrupal+48 | 29/4/2020 | 17/6/2026 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Media (5.3) | 2.4% | — | Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications BRM - Elastic Charging EngineOracle Communications Diameter Signaling Router+23 | 17/1/2020 | 17/6/2026 | Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and… | |
| Modificada | Alta (7.5) | 89% | — | Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Policy+29 | 17/1/2020 | 17/6/2026 | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input. | |
| Modificada | Alta (7.5) | 1.8% | — | Oracle Application Testing Suite | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Oracle Flow Builder). Supported versions that are affected are 12.5.0.3, 13.1.0.1, 13.2.0.1 and 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Modificada | Alta (8.8) | 11% | — | OpencvOracle Application Testing SuiteOracle BIG Data Spatial AND GraphOracle Enterprise Manager Base Platform | 3/1/2020 | 17/6/2026 | An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to… | |
| Modificada | Alta (8.8) | 21% | — | OpencvOracle Application Testing SuiteOracle BIG Data Spatial AND GraphOracle Enterprise Manager Base Platform | 3/1/2020 | 17/6/2026 | An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this… | |
| Modificada | Crítica (9.8) | 69% | — | Apache Log4jDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+13 | 20/12/2019 | 17/6/2026 | Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17. | |
| Modificada | Media (6.1) | 2.2% | — | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Media (5.5) | 1.00% | — | Apache POIOracle Application Testing SuiteOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+23 | 23/10/2019 | 17/6/2026 | In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing. | |
| Modificada | Crítica (9.8) | 14% | — | Oracle Application Testing SuiteOracle Banking Enterprise CollectionsOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+18 | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and… | |
| Modificada | Media (6.1) | 2.5% | — | Eclipse MojarraOracle Mojarra Javaserver FacesOracle Application Testing SuiteOracle Banking Enterprise Product Manufacturing+19 | 2/10/2019 | 17/6/2026 | faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled. | |
| Modificada | Alta (7.3) | 28% | — | Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+56 | 20/8/2019 | 25/8/2026 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | |
| Modificada | Alta (7.3) | 1.2% | — | Oracle Application Testing Suite | 23/7/2019 | 17/6/2026 | Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponent: Load Testing for Web Apps). The supported version that is affected is 13.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (7.5) | 92% | — | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+33 | 1/5/2019 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version… | |
| Modificada | Media (6.3) | 5.4% | — | Oracle Application Testing Suite | 23/4/2019 | 17/6/2026 | Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponent: Load Testing for Web Apps). The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… |