Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Soapmakingforum Soap Making | 26/9/2014 | 17/6/2026 | The Soap Making (aka com.tapatalk.soapmakingforumcom) application 3.7.13 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 2.7% | — | Makina-corpus Soappy | 12/5/2014 | 17/6/2026 | SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references. | |
| Modificada | Media (5) | 1.8% | — | Makina-corpus Soappy | 12/5/2014 | 17/6/2026 | SOAPpy 0.12.5 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Alta (9.3) | 7.7% | 💥 Exploit | Eviware SoapuiSmartbear Soapui | 25/1/2014 | 17/6/2026 | The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file. | |
| Modificada | Media (5.8) | 5.7% | — | Apache ActivemqApache AxisPaypal Mass PAYPaypal Payments PRO+1 | 4/11/2012 | 16/6/2026 | Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field… | |
| Modificada | Media (5) | 1.4% | — | Dietrich Ayala Nusoap | 24/9/2011 | 16/6/2026 | NuSOAP 0.9.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by nuSOAP/classes/class.wsdl.php and certain other files. | |
| Modificada | Media (4.3) | 6.2% | 💥 Exploit | Dietrich Ayala Nusoap | 28/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in NuSOAP 0.9.5, as used in MantisBT and other products, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to an arbitrary PHP script that uses NuSOAP classes. | |
| Modificada | Media (6.9) | 0.39% | — | Savonet Liguidsoap | 6/11/2008 | 16/6/2026 | liguidsoap.py in liguidsoap 0.3.8.1+2 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/liguidsoap.liq, (2) /tmp/lig.#####.log, and (3) /tmp/emission.ogg temporary files. | |
| Modificada | Media (5) | 1.6% | — | Paul Kulchenko Soap Lite | 31/12/2002 | 16/6/2026 | SOAP::Lite 0.50 through 0.52 allows remote attackers to load arbitrary Perl functions by suppling a non-existent function in a script using a SOAP::Lite module, which causes the AUTOLOAD subroutine to trigger. |