Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could be able to upload arbitrary files without authentication. Please note that an attacker needs to have network access to the Application Server in… | |
| Modificada | Alta (7.5) | 1.1% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is independent from CVE-2019-18317 and… | |
| Modificada | Alta (7.5) | 1.1% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server can cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is independent from CVE-2019-18317 and… | |
| Modificada | Alta (7.5) | 1.1% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is independent from CVE-2019-18318 and… | |
| Modificada | Crítica (9.8) | 2.7% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 1099/tcp. Please note that an attacker needs to have network access to the… | |
| Modificada | Crítica (9.8) | 2.5% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 8888/tcp. Please note that an attacker needs to have network access to the… | |
| Modificada | Crítica (9.8) | 2.3% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted objects via RMI. Please note that an attacker needs to have network access to the… | |
| Modificada | Alta (8.8) | 4.0% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with valid authentication at the RMI interface could be able to gain remote code execution through an unsecured file upload. Please note that an attacker needs to have access to the Application… | |
| Modificada | Media (5.3) | 1.6% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes directory listings and files containing sensitive information. This vulnerability is independent from CVE-2019-18286. Please note that an attacker needs to have access to the… | |
| Modificada | Media (5.3) | 1.6% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes directory listings and files containing sensitive information. This vulnerability is independent from CVE-2019-18287. Please note that an attacker needs to have access to the… | |
| Modificada | Media (5.9) | 1.0% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The RMI communication between the client and the Application Server is unencrypted. An attacker with access to the communication channel can read credentials of a valid user. Please note that an attacker needs… | |
| Modificada | Crítica (9.8) | 2.0% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can use methods exposed via this interface to receive password hashes of other users and to change user passwords.… | |
| Modificada | Crítica (9.8) | 5.4% | — | Siemens Sppa-t3000 Application Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can gain remote code execution by sending specifically crafted objects to one of its functions. Please note that an… | |
| Modificada | Media (5.4) | 2.2% | 💥 Exploit | Avaya IP Office Application Server | 12/12/2019 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affected. Product versions prior to 11.0, including unsupported versions, were not evaluated. | |
| Modificada | Media (5.4) | 0.60% | — | IBM Websphere Application Server | 10/12/2019 | 17/6/2026 | IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171245. | |
| Modificada | Baja (3.3) | 0.32% | — | Redhat Jboss Community Application ServerRedhat Jboss Enterprise WEB Server | 6/12/2019 | 16/6/2026 | An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Jboss Application Server | 26/11/2019 | 16/6/2026 | A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a… | |
| Modificada | Media (5.4) | 1.1% | — | Redhat Jboss Application Server | 26/11/2019 | 16/6/2026 | A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment… | |
| Modificada | Alta (7.5) | 2.3% | — | Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+23 | 15/11/2019 | 17/6/2026 | A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service. | |
| Modificada | Media (4.3) | 0.89% | — | SAP Netweaver Application Server Java | 13/11/2019 | 17/6/2026 | Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted. | |
| Modificada | Alta (8.8) | 1.3% | — | SAP Netweaver Application Server Java | 13/11/2019 | 17/6/2026 | An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Media (5.5) | 1.00% | — | Apache POIOracle Application Testing SuiteOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+23 | 23/10/2019 | 17/6/2026 | In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing. | |
| Modificada | Crítica (9.8) | 5.4% | — | Fasterxml Jackson-databindDebian LinuxRedhat Jboss Enterprise Application PlatformOracle Banking Platform+18 | 12/10/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide… | |
| Modificada | Media (5.3) | 1.6% | — | IBM Websphere Application Server | 3/10/2019 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177. |