Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.21% | — | Wielebenwir Commonsbooking | 21/6/2024 | 17/6/2026 | The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks | |
| Modificada | Media (4.8) | 0.33% | — | Wielebenwir Commonsbooking | 21/6/2024 | 17/6/2026 | The CB (legacy) WordPress plugin through 0.9.4.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (5.4) | 1.7% | — | Apache Commons ConfigurationFedoraproject Fedora | 21/3/2024 | 17/6/2026 | Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | |
| Analizada | Alta (7.3) | 2.1% | — | Apache Commons ConfigurationFedoraproject FedoraNetapp Ontap ToolsNetapp Snapcenter | 21/3/2024 | 17/6/2026 | Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | |
| Modificada | Media (5.5) | 0.90% | 💥 PoC | Apache Commons Compress | 19/2/2024 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue. | |
| Modificada | Media (5.5) | 0.44% | — | Apache Commons Compress | 19/2/2024 | 17/6/2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue. | |
| Modificada | Media (5.5) | 0.60% | — | Apache Commons Compress | 14/9/2023 | 17/6/2026 | Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0. Users are recommended to upgrade to version 1.24.0, which fixes the issue. A third party can create a malformed TAR file by… | |
| Modificada | Media (5.4) | 1.0% | 💥 PoC | Xwiki Commons | 29/6/2023 | 17/6/2026 | Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without script right to either create forms that can be used for phishing attacks or also in… | |
| Modificada | Crítica (9.8) | 2.2% | — | Apache Sling Commons Json | 15/5/2023 | 17/6/2026 | Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are encouraged to consider the Apache Sling… | |
| Modificada | Crítica (9) | 1.3% | 💥 PoC | Xwiki Commons | 20/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1 and massively improved in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus cross-site scripting via invalid HTML… | |
| Modificada | Crítica (9.9) | 1.2% | — | Xwiki Commons | 2/3/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The same vulnerability can also be exploited in all other places where short text… | |
| Modificada | Alta (7.5) | 49% | 💥 PoC | Apache Commons FileuploadDebian Linux | 20/2/2023 | 17/6/2026 | Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. | |
| Modificada | Alta (8.1) | 0.71% | — | Siemens Mendix Workflow Commons | 13/12/2022 | 17/6/2026 | A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0), Mendix Workflow Commons V2.1 (All versions < V2.1.4), Mendix Workflow Commons V2.3 (All versions < V2.3.2). Affected versions of the module improperly handle access control for some module entities. This could allow authenticated… | |
| Modificada | Media (6.5) | 2.1% | — | Apache Commons NETDebian Linux | 3/12/2022 | 17/6/2026 | Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the… | |
| Modificada | Crítica (9.8) | 3.0% | — | Apache Commons BcelFedoraproject Fedora | 7/11/2022 | 17/6/2026 | Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the… | |
| Modificada | Crítica (9.8) | 100% | 💥 Exploit | Apache Commons TextNetapp BluexpJuniper Security Threat Response Manager | 13/10/2022 | 17/6/2026 | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with… | |
| Modificada | Media (6.5) | 1.4% | — | Apache Commons Jxpath | 6/10/2022 | 17/6/2026 | ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then allocated by Google in breach of the CNA rules. After… | |
| Modificada | Media (6.5) | 1.4% | — | Apache Commons Jxpath | 6/10/2022 | 17/6/2026 | ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then allocated by Google in breach of the CNA rules. After… | |
| Modificada | Crítica (9.8) | 45% | 💥 PoC | Apache Commons ConfigurationNetapp SnapcenterDebian Linux | 6/7/2022 | 17/6/2026 | Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation.… | |
| Modificada | Media (5.3) | 2.4% | — | Apache Sling APIApache Sling Commons LOG | 22/6/2022 | 17/6/2026 | Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files. | |
| Modificada | Media (4.9) | 1.5% | — | Xwiki Commons | 28/4/2022 | 17/6/2026 | org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the user running XWiki application server with XML External Entity Injection through… | |
| Modificada | Media (6.1) | 1.1% | — | Adobe ACS AEM Commons | 21/4/2022 | 17/6/2026 | ACS Commons version 5.1.x (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in /apps/acs-commons/content/page-compare.html endpoint via the a and b GET parameters. User input submitted via these parameters is not validated or sanitised. An attacker must provide a link to someone with… | |
| Modificada | Crítica (9.8) | 8.6% | 💥 Exploit | Wielebenwir Commonsbooking | 14/3/2022 | 17/6/2026 | The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection | |
| Modificada | Alta (8.8) | 2.3% | 💥 PoC | Jenkins Docker Commons | 12/1/2022 | 17/6/2026 | Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository. | |
| Modificada | Alta (7.4) | 1.9% | — | Apache Sling Commons Messaging Mail | 14/12/2021 | 17/6/2026 | Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "man in the middle" attacks additional server identity checks must be performed when accessing mail servers. For compatibility reasons these additional checks are disabled… |