Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
180 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 2.8% | — | Oracle GraalvmOracle Http ServerOracle JDKOracle JRE+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker… | |
| Modificada | Baja (3.7) | 3.8% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+16 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Difficult to exploit vulnerability allows… | |
| Modificada | Crítica (9.8) | 67% | 💥 PoC | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+24 | 18/1/2022 | 17/6/2026 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or… | |
| Modificada | Alta (8.8) | 64% | — | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+22 | 18/1/2022 | 17/6/2026 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink… | |
| Modificada | Baja (3.7) | 4.4% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Modificada | Baja (3.1) | 3.9% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u311, 8u301; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access… | |
| Modificada | Media (5.3) | 6.8% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Media (5.3) | 6.7% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access… | |
| Analizada | Media (6.8) | 2.9% | — | Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+12 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows low privileged attacker with network… | |
| Modificada | Media (5.3) | 7.4% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.3) | 5.6% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Keytool). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Media (5.3) | 6.9% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Utility). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Media (5.3) | 16% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.3) | 8.5% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.9) | 7.4% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+9 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Analizada | Alta (8.5) | 11% | 💥 Exploit | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected,… | |
| Analizada | Alta (8.5) | 3.4% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected,… | |
| Analizada | Media (6.3) | 5.9% | — | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.5% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+9 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 14% | 💥 Exploit | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… |