Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Crítica (9.8) | 14% | — | Apache CXFOracle Commerce Guided SearchOracle Enterprise Manager Base PlatformOracle Flexcube Private Banking+1 | 6/11/2019 | 17/6/2026 | Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If… | |
| Modificada | Media (6.5) | 6.3% | — | Apache CXFOracle Commerce Guided SearchOracle Flexcube Private BankingOracle Retail Order Broker | 6/11/2019 | 17/6/2026 | Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a… | |
| Modificada | Media (5.5) | 1.00% | — | Apache POIOracle Application Testing SuiteOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+23 | 23/10/2019 | 17/6/2026 | In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing. | |
| Modificada | Crítica (9.8) | 14% | — | Oracle Application Testing SuiteOracle Banking Enterprise CollectionsOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+18 | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and… | |
| Modificada | Alta (7.5) | 8.9% | — | Bouncycastle Bc-javaApache TomeeNetapp Active IQ Unified ManagerNetapp Oncommand API Services+17 | 8/10/2019 | 17/6/2026 | The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64. | |
| Modificada | Alta (7.5) | 16% | — | Apache Commons CompressFedoraproject FedoraOracle Banking PaymentsOracle Banking Platform+15 | 30/8/2019 | 17/6/2026 | The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress. | |
| Modificada | Alta (7.3) | 28% | — | Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+56 | 20/8/2019 | 25/8/2026 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | |
| Modificada | Crítica (9.8) | 16% | 💥 PoC | Softwareag QuartzOracle Apache Batik MapviewerOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+27 | 26/7/2019 | 17/6/2026 | initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. | |
| Modificada | Alta (7.5) | 9.8% | — | Apache CamelOracle Enterprise Data QualityOracle Enterprise Manager Base PlatformOracle Flexcube Private Banking+1 | 28/5/2019 | 17/6/2026 | Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed. | |
| Modificada | Alta (7.5) | 92% | 💥 Exploit | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+33 | 1/5/2019 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version… | |
| Analizada | Alta (7.5) | 4.9% | 💥 PoC | Mchange C3p0Fedoraproject FedoraOracle Communications IP Service ActivatorOracle Communications Session Route Manager+7 | 22/4/2019 | 17/6/2026 | c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration. | |
| Modificada | Media (5.3) | 5.9% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+22 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path.… | |
| Modificada | Media (5.3) | 4.1% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+21 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in… | |
| Modificada | Crítica (9.8) | 4.1% | — | Broadcom Spring WEB ServicesOracle Financial Services Analytical Applications InfrastructureOracle Flexcube Private Banking | 18/1/2019 | 4/9/2026 | Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. | |
| Modificada | Alta (7.5) | 9.2% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Communications BRM - Elastic Charging EngineOracle Communications Converged Application Server - Service Controller+36 | 18/10/2018 | 25/8/2026 | Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an… | |
| Modificada | Alta (7.4) | 7.0% | — | Apache ActivemqOracle Enterprise RepositoryOracle Flexcube Private Banking | 10/9/2018 | 17/6/2026 | TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default. | |
| Modificada | Media (6.1) | 11% | 💥 PoC | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+34 | 2/8/2018 | 17/6/2026 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. | |
| Modificada | Alta (7.5) | 3.2% | — | Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Network Integrity+24 | 25/6/2018 | 17/6/2026 | Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not… | |
| Modificada | Media (6.5) | 3.0% | — | Vmware Spring FrameworkRedhat OpenshiftOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+26 | 11/5/2018 | 17/6/2026 | Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that… | |
| Modificada | Media (5.9) | 5.1% | — | Google GuavaRedhat Openshift Container PlatformRedhat OpenstackRedhat Satellite+13 | 26/4/2018 | 17/6/2026 | Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the… | |
| Modificada | Media (6.5) | 1.7% | — | Oracle Flexcube Private Banking | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.5) | 1.9% | — | Oracle Flexcube Private Banking | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (4.3) | 1.4% | — | Oracle Flexcube Private Banking | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (5.4) | 1.2% | — | Oracle Flexcube Private Banking | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… |