Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 3.4% | — | Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+8 | 12/6/2021 | 17/6/2026 | In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. | |
| Modificada | Alta (8.8) | 77% | 💥 Exploit | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+13 | 28/5/2021 | 17/6/2026 | XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's… | |
| Modificada | Media (5.9) | 4.9% | — | NettyDebian LinuxNetapp Oncommand API ServicesNetapp Oncommand Workflow Automation+14 | 30/3/2021 | 17/6/2026 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not… | |
| Modificada | Media (5.5) | 3.3% | — | Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+15 | 19/3/2021 | 17/6/2026 | A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. | |
| Modificada | Media (5.5) | 3.0% | — | Apache PdfboxFedoraproject FedoraOracle Banking Trade Finance Process ManagementOracle Banking Treasury Management+11 | 19/3/2021 | 17/6/2026 | A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. | |
| Modificada | Alta (7.2) | 21% | 💥 Exploit | LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+19 | 15/2/2021 | 17/6/2026 | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | |
| Modificada | Media (5.3) | 7.3% | — | LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+15 | 15/2/2021 | 17/6/2026 | Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. | |
| Modificada | Media (5.5) | 1.8% | — | NettyDebian LinuxQuarkusOracle Banking Corporate Lending Process Management+9 | 8/2/2021 | 17/6/2026 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are… | |
| Analizada | Alta (8.8) | 85% | 💥 Exploit | XstreamDebian LinuxNetapp SnapmanagerApache Activemq+11 | 16/11/2020 | 17/6/2026 | XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The… | |
| Modificada | Alta (7.4) | 5.2% | — | LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+14 | 15/7/2020 | 17/6/2026 | Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. | |
| Modificada | Alta (7.5) | 3.9% | — | Apache KafkaOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Liquidity Management+9 | 14/1/2020 | 17/6/2026 | When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can… | |
| Modificada | Crítica (9.8) | 9.5% | — | Apache PdfboxApache JamesFedoraproject FedoraOracle Banking Corporate Lending Process Management+10 | 17/4/2019 | 17/6/2026 | Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF. |