Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2500▼ 420 respecto a la semana anterior
Críticas / altas1284▲ 11 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

943 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)0.84%—Shibboleth Identity ProviderShibboleth Opensaml Java4/4/201917/6/2026
The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle…
ModificadaMedia (5.4)0.78%—SAP Netweaver Application Server Java12/3/201917/6/2026
SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50, does not sufficiently encode user-controlled inputs, which results in cross-site scripting (XSS) vulnerability.
ModificadaAlta (7.5)7.4%—Microsoft Java Software Development KIT5/3/201917/6/2026
An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'.
ModificadaCrítica (9.8)3.1%—Microsoft Java Software Development KIT5/3/201917/6/2026
An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'.
ModificadaMedia (5.3)9.4%—LibpngDebian LinuxCanonical Ubuntu LinuxOracle Hyperion Infrastructure Technology+284/2/201917/6/2026
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
ModificadaMedia (6.1)1.5%—Oracle Java Advanced Management Console16/1/201917/6/2026
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java…
AnalizadaCrítica (9.8)1.7%—Wxjava Project Wxjava4/1/201917/6/2026
An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318.
ModificadaMedia (5.3)1.8%—Hubspot Jinjava3/1/201917/6/2026
Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java.
ModificadaCrítica (9.8)1.7%—Wxjava Project Wxjava21/12/201817/6/2026
An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.
ModificadaMedia (6.5)4.8%—Fasterxml Jackson-modules-java8Oracle ClusterwareOracle Database ServerOracle Global Lifecycle Management Opatch+220/12/201817/6/2026
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a…
ModificadaMedia (6.1)1.1%—SAP Netweaver Application Server Java11/12/201817/6/2026
SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50.
ModificadaAlta (7.4)0.57%—SAP Netweaver Application Server Java11/12/201817/6/2026
By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be protected. This has been fixed in SAP NetWeaver AS Java (ServerCore versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50).
ModificadaAlta (7.1)1.1%—SAP Netweaver Application Server Java11/12/201817/6/2026
SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in versions 7.2, 7.30, 7.31, 7.40 and 7.50.
ModificadaAlta (7.5)2.4%—Linlinjava Litemall17/10/201817/6/2026
An issue was discovered in litemall 0.9.0. Arbitrary file download is possible via ../ directory traversal in linlinjava/litemall/wx/web/WxStorageController.java in the litemall-wx-api component.
ModificadaCrítica (9.8)28%—Javamelody Project Javamelody26/9/201817/6/2026
JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.
ModificadaAlta (8.2)1.6%—Opcfoundation Ua-.net-legacyOpcfoundation Ua-java14/9/201817/6/2026
An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.
ModificadaAlta (7.5)12%—Opcfoundation Unified Architecture-.net-legacyOpcfoundation Unified Architecture-javaOpcfoundation Unified Architecture .net-standardOpcfoundation Unified Architecture Ansic+114/9/201817/6/2026
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
AnalizadaMedia (5.9)1.2%—Pivotal Software Spring Advanced Message Queuing ProtocolVmware Rabbitmq Java Client14/9/201817/6/2026
Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit.
ModificadaMedia (5.6)2.1%—Microsoft C Software Development KITMicrosoft Java Software Development KIT13/9/201817/6/2026
A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure IoT SDK Spoofing Vulnerability." This affects C SDK.
ModificadaMedia (6.1)1.4%—SAP Netweaver Application Server Java11/9/201817/6/2026
The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, resulting in a cross-site scripting (XSS) vulnerability.
ModificadaMedia (6.1)1.3%—Javasystemsolutions SSO Plugin21/8/201817/6/2026
Reflected Cross-Site Scripting exists in the Java System Solutions SSO plugin 4.0.13.1 for BMC MyIT. A remote attacker can abuse this issue to inject client-side scripts into the "select_sso()" function. The payload is triggered when the victim opens a prepared /ux/jss-sso/arslogin?[XSS] link and then clicks the…
ModificadaMedia (5.9)1.6%—Cloudfoundry Cf-releaseCloudfoundry Java Buildpack11/7/201817/6/2026
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications to be vulnerable, they must have been staged using automatic buildpack detection, passed through…
ModificadaCrítica (9.8)7.5%—Microsoft Research Javascript Cryptography Library11/7/201817/6/2026
A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka "MSR JavaScript Cryptography Library Security Feature Bypass Vulnerability." This affects Microsoft Research JavaScript Cryptography Library.
ModificadaCrítica (9.8)4.8%—Bouncycastle Bc-javaNetapp Oncommand Workflow AutomationOpensuse LeapOracle API Gateway+209/7/201817/6/2026
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an…
ModificadaAlta (7.5)0.88%—Javaswaptest Project Javaswaptest4/7/201817/6/2026
The mintToken function of a smart contract implementation for JavaSwapTest (JST), an Ethereum token, has an integer overflow.