Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.33% | — | Zenspider Ruby Parser-legacy | 24/10/2019 | 17/6/2026 | The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files. For example, if the brakeman gem (which has a legacy dependency) 4.5.0 through 4.7.0 is used, a local user can insert malicious code into the… | |
| Modificada | Media (5.3) | 0.29% | — | Opcfoundation Ua-.net-legacyOpcfoundation Ua-.netstandard | 3/10/2018 | 17/6/2026 | Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece of network infrastructure to decrypt passwords. | |
| Modificada | Alta (8.2) | 1.6% | — | Opcfoundation Ua-.net-legacyOpcfoundation Ua-java | 14/9/2018 | 17/6/2026 | An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service. | |
| Modificada | Alta (7.5) | 12% | 💥 PoC | Opcfoundation Unified Architecture-.net-legacyOpcfoundation Unified Architecture-javaOpcfoundation Unified Architecture .net-standardOpcfoundation Unified Architecture Ansic+1 | 14/9/2018 | 17/6/2026 | Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests. | |
| Modificada | Alta (8.8) | 1.0% | — | Opcfoundation Ua-.net-legacy | 14/6/2018 | 17/6/2026 | Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code. | |
| Modificada | Media (5.3) | 1.2% | — | Opcfoundation Ua-.net-legacyOpcfoundation Ua-.netstandard | 13/6/2018 | 17/6/2026 | An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code before GitHub commit 2018-03-13. A vulnerability in OPC UA applications can allow a remote attacker to determine a Server's private key by sending carefully constructed… | |
| Modificada | Alta (8.1) | 1.4% | — | Hcltech Legacy IVR Firmware | 30/5/2018 | 17/6/2026 | A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio signals; based on the frequency, certain commands and functions are processed. Since these frequencies are accepted within a phone call, an attacker can record these… | |
| Modificada | Media (5.9) | 0.49% | — | Meafinancial Your Legacy Federal Credit Union Mobile Banking | 16/6/2017 | 17/6/2026 | The "Your Legacy Federal Credit Union Mobile Banking" by Your Legacy Federal Credit Union app 3.0.1 -- aka your-legacy-federal-credit-union-mobile-banking/id919131389 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information… | |
| Modificada | Alta (8.1) | 5.7% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Module FOR Legacy SoftwareNovell Suse Linux Enterprise ServerNovell Suse Manager+9 | 3/6/2016 | 17/6/2026 | The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block,… | |
| Modificada | Alta (8.1) | 4.0% | — | Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node SupplementaryRedhat Enterprise Linux Server+9 | 3/6/2016 | 17/6/2026 | The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController… | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa | Oracle JDKOracle JREOracle JrockitOracle Linux+34 | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. | |
| Analizada | Media (5.3) | 14% | ⚠ Explotación activa | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+17 | 22/10/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment. | |
| Modificada | Media (6.4) | 1.0% | — | Ubermedia Twidroyd Legacy | 25/1/2012 | 16/6/2026 | The Ubermedia Twidroyd Legacy (com.twidroydlegacy) application 4.3.11 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application. | |
| Modificada | Baja (2.1) | 0.35% | — | GNU Grub Legacy | 3/9/2008 | 16/6/2026 | Grub Legacy 0.97 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer. | |
| Modificada | Alta (7.5) | 1.5% | — | Watchguard Legacy RssaWatchguard SohoWatchguard Vclass | 31/12/2002 | 16/6/2026 | WatchGuard SOHO products running firmware 5.1.6 and earlier, and Vclass/RSSA using 3.2 SP1 and earlier, allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat… |