Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.1% | — | Apache Sling JCR Contentloader | 9/1/2018 | 16/6/2026 | The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information leaks. Users should upgrade to version 2.1.6 of the JCR ContentLoader | |
| Modificada | Alta (8.8) | 1.9% | — | Apache Sling Authentication Service | 18/12/2017 | 17/6/2026 | A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials. | |
| Modificada | Media (6.1) | 3.7% | — | Apache Sling Servlets Post | 14/8/2017 | 17/6/2026 | The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, which allows for XSS attacks by passing specially crafted input strings. | |
| Modificada | Crítica (9.8) | 3.7% | — | Apache Sling | 19/7/2017 | 17/6/2026 | In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowing an attacker to read sensitive data on the filesystem,… | |
| Modificada | Media (6.1) | 2.6% | — | Apache Sling | 19/7/2017 | 17/6/2026 | In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough and for some input patterns allows script tags to pass through unencoded, leading to potential XSS vulnerabilities. | |
| Modificada | Alta (7.5) | 51% | — | Apache SlingAdobe Experience Manager | 10/2/2016 | 17/6/2026 | The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (4) | 2.3% | — | Tibco Managed File Transfer Internet ServerTibco VaultTibco Managed File Transfer Command CenterTibco Slingshot | 29/9/2015 | 17/6/2026 | TIBCO Managed File Transfer Internet Server before 7.2.5, Managed File Transfer Command Center before 7.2.5, Slingshot before 1.9.4, and Vault before 2.0.1 allow remote authenticated users to obtain sensitive information via a crafted HTTP request. | |
| Modificada | Media (4.3) | 6.3% | — | Apache Sling APIApache Sling Servlets Post | 2/6/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse. | |
| Modificada | Media (6.4) | 1.1% | — | Tibco Managed File Transfer Internet ServerTibco Managed File Transfer Command CenterTibco SlingshotTibco Vault | 21/11/2014 | 17/6/2026 | TIBCO Managed File Transfer Internet Server before 7.2.4, Managed File Transfer Command Center before 7.2.4, Slingshot before 1.9.3, and Vault before 1.1.1 allow remote attackers to obtain sensitive information or modify data by leveraging agent access. | |
| Modificada | Media (5.4) | 0.27% | — | Gcspublishing Slingshot Forum | 21/10/2014 | 17/6/2026 | The Slingshot Forum (aka com.tapatalk.theslingshotforumcom) application 3.9.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Slingo Lottery Challenge | 9/9/2014 | 17/6/2026 | The Slingo Lottery Challenge (aka com.slingo.slingolotterychallenge) application 1.0.34 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.8% | — | Tibco SlingshotTibco VaultTibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server | 30/4/2014 | 17/6/2026 | TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot before 1.9.1, and Vault before 1.0.1 allow remote attackers to obtain sensitive information via a crafted HTTP request. | |
| Modificada | Media (5.8) | 3.1% | — | Apache SlingApache Sling Auth Core Component | 24/10/2013 | 16/6/2026 | Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Sling allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the resource parameter, related to "a custom login form and… | |
| Modificada | Media (5) | 4.1% | — | Org.apache.sling.servlets.post | 17/10/2013 | 16/6/2026 | The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that returned when the session does not have permissions to the root node, which allows remote attackers to cause a denial of… | |
| Modificada | Media (5) | 14% | — | Org.apache.sling.servlets.post | 9/7/2012 | 16/6/2026 | The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request. | |
| Modificada | Media (4.3) | 1.3% | — | Tibco Managed File Transfer Command CenterTibco Managed File Transfer Internet ServerTibco Slingshot | 19/9/2011 | 16/6/2026 | Session fixation vulnerability in the Managed File Transfer server in TIBCO Managed File Transfer Internet Server before 7.1.1 and Managed File Transfer Command Center before 7.1.1, and the server in TIBCO Slingshot before 1.8.1, allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Tibco Managed File Transfer Command CenterTibco Managed File Transfer Internet ServerTibco Slingshot | 19/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Managed File Transfer server in TIBCO Managed File Transfer Internet Server before 7.1.1 and Managed File Transfer Command Center before 7.1.1, and the server in TIBCO Slingshot before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via unspecified… |