Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 3.8% | — | Oracle GraalvmOracle JDKOracle JREDebian Linux+16 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Media (5.3) | 2.9% | — | Oracle GraalvmOracle JDKOracle JREDebian Linux+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated… | |
| Modificada | Media (5.3) | 3.1% | — | Oracle GraalvmOracle JDKOracle JREDebian Linux+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Baja (3.7) | 3.8% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+16 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Difficult to exploit vulnerability allows… | |
| Modificada | Baja (3.7) | 4.4% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Modificada | Baja (3.1) | 3.9% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u311, 8u301; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access… | |
| Modificada | Media (5.3) | 6.8% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Media (5.3) | 6.7% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access… | |
| Analizada | Media (6.8) | 2.9% | — | Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+12 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows low privileged attacker with network… | |
| Modificada | Media (5.3) | 7.4% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.3) | 5.6% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Keytool). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Media (5.3) | 6.9% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Utility). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Alta (7.5) | 4.8% | — | Oracle OpenjdkNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage ManagerNetapp E-series Santricity WEB Services+2 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction… | |
| Modificada | Media (5.3) | 16% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.3) | 8.5% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.9) | 7.4% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+9 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Modificada | Alta (7.8) | 0.27% | — | Oracle Openjdk | 6/10/2021 | 17/6/2026 | An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with access to the container to modify the /etc/passwd and escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system… | |
| Analizada | Alta (7.5) | 4.0% | — | Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+1 | 21/7/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Analizada | Media (4.3) | 3.4% | — | Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+1 | 21/7/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Library). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Analizada | Baja (3.1) | 4.2% | — | Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+2 | 21/7/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker… | |
| Modificada | Media (5.5) | 0.32% | — | Canonical Ubuntu LinuxOracle Openjdk | 12/6/2021 | 17/6/2026 | It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users. | |
| Modificada | Media (5.5) | 5.4% | — | GstreamerNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage Manager+8 | 2/6/2021 | 17/6/2026 | GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags. | |
| Modificada | Alta (8.6) | 17% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Enterprise LinuxFedoraproject Fedora+24 | 19/5/2021 | 17/6/2026 | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application… | |
| Modificada | Media (5.9) | 3.5% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Enterprise LinuxDebian Linux+15 | 14/5/2021 | 17/6/2026 | A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this… | |
| Modificada | Media (5.3) | 3.6% | — | Oracle JDKOracle JREDebian LinuxFedoraproject Fedora+7 | 22/4/2021 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to… |