Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2500▼ 420 respecto a la semana anterior
Críticas / altas1284▲ 11 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
943 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.84% | — | Shibboleth Identity ProviderShibboleth Opensaml Java | 4/4/2019 | 17/6/2026 | The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle… | |
| Modificada | Media (5.4) | 0.78% | — | SAP Netweaver Application Server Java | 12/3/2019 | 17/6/2026 | SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50, does not sufficiently encode user-controlled inputs, which results in cross-site scripting (XSS) vulnerability. | |
| Modificada | Alta (7.5) | 7.4% | — | Microsoft Java Software Development KIT | 5/3/2019 | 17/6/2026 | An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'. | |
| Modificada | Crítica (9.8) | 3.1% | — | Microsoft Java Software Development KIT | 5/3/2019 | 17/6/2026 | An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'. | |
| Modificada | Media (5.3) | 9.4% | — | LibpngDebian LinuxCanonical Ubuntu LinuxOracle Hyperion Infrastructure Technology+28 | 4/2/2019 | 17/6/2026 | png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute. | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Java Advanced Management Console | 16/1/2019 | 17/6/2026 | Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java… | |
| Analizada | Crítica (9.8) | 1.7% | — | Wxjava Project Wxjava | 4/1/2019 | 17/6/2026 | An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318. | |
| Modificada | Media (5.3) | 1.8% | — | Hubspot Jinjava | 3/1/2019 | 17/6/2026 | Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java. | |
| Modificada | Crítica (9.8) | 1.7% | — | Wxjava Project Wxjava | 21/12/2018 | 17/6/2026 | An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. | |
| Modificada | Media (6.5) | 4.8% | — | Fasterxml Jackson-modules-java8Oracle ClusterwareOracle Database ServerOracle Global Lifecycle Management Opatch+2 | 20/12/2018 | 17/6/2026 | Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a… | |
| Modificada | Media (6.1) | 1.1% | — | SAP Netweaver Application Server Java | 11/12/2018 | 17/6/2026 | SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50. | |
| Modificada | Alta (7.4) | 0.57% | — | SAP Netweaver Application Server Java | 11/12/2018 | 17/6/2026 | By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be protected. This has been fixed in SAP NetWeaver AS Java (ServerCore versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50). | |
| Modificada | Alta (7.1) | 1.1% | — | SAP Netweaver Application Server Java | 11/12/2018 | 17/6/2026 | SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in versions 7.2, 7.30, 7.31, 7.40 and 7.50. | |
| Modificada | Alta (7.5) | 2.4% | — | Linlinjava Litemall | 17/10/2018 | 17/6/2026 | An issue was discovered in litemall 0.9.0. Arbitrary file download is possible via ../ directory traversal in linlinjava/litemall/wx/web/WxStorageController.java in the litemall-wx-api component. | |
| Modificada | Crítica (9.8) | 28% | — | Javamelody Project Javamelody | 26/9/2018 | 17/6/2026 | JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java. | |
| Modificada | Alta (8.2) | 1.6% | — | Opcfoundation Ua-.net-legacyOpcfoundation Ua-java | 14/9/2018 | 17/6/2026 | An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service. | |
| Modificada | Alta (7.5) | 12% | — | Opcfoundation Unified Architecture-.net-legacyOpcfoundation Unified Architecture-javaOpcfoundation Unified Architecture .net-standardOpcfoundation Unified Architecture Ansic+1 | 14/9/2018 | 17/6/2026 | Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests. | |
| Analizada | Media (5.9) | 1.2% | — | Pivotal Software Spring Advanced Message Queuing ProtocolVmware Rabbitmq Java Client | 14/9/2018 | 17/6/2026 | Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit. | |
| Modificada | Media (5.6) | 2.1% | — | Microsoft C Software Development KITMicrosoft Java Software Development KIT | 13/9/2018 | 17/6/2026 | A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure IoT SDK Spoofing Vulnerability." This affects C SDK. | |
| Modificada | Media (6.1) | 1.4% | — | SAP Netweaver Application Server Java | 11/9/2018 | 17/6/2026 | The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, resulting in a cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 1.3% | — | Javasystemsolutions SSO Plugin | 21/8/2018 | 17/6/2026 | Reflected Cross-Site Scripting exists in the Java System Solutions SSO plugin 4.0.13.1 for BMC MyIT. A remote attacker can abuse this issue to inject client-side scripts into the "select_sso()" function. The payload is triggered when the victim opens a prepared /ux/jss-sso/arslogin?[XSS] link and then clicks the… | |
| Modificada | Media (5.9) | 1.6% | — | Cloudfoundry Cf-releaseCloudfoundry Java Buildpack | 11/7/2018 | 17/6/2026 | Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications to be vulnerable, they must have been staged using automatic buildpack detection, passed through… | |
| Modificada | Crítica (9.8) | 7.5% | — | Microsoft Research Javascript Cryptography Library | 11/7/2018 | 17/6/2026 | A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka "MSR JavaScript Cryptography Library Security Feature Bypass Vulnerability." This affects Microsoft Research JavaScript Cryptography Library. | |
| Modificada | Crítica (9.8) | 4.8% | — | Bouncycastle Bc-javaNetapp Oncommand Workflow AutomationOpensuse LeapOracle API Gateway+20 | 9/7/2018 | 17/6/2026 | Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an… | |
| Modificada | Alta (7.5) | 0.88% | — | Javaswaptest Project Javaswaptest | 4/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for JavaSwapTest (JST), an Ethereum token, has an integer overflow. |