Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
943 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.6% | — | Articatech Artica Proxy | 5/5/2022 | 17/6/2026 | A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp. | |
| Modificada | Media (4.3) | 0.82% | — | Fortinet FortiproxyFortinet Fortios | 4/5/2022 | 17/6/2026 | A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client username and IP via same origin HTTP requests triggering proxy-generated… | |
| Modificada | Alta (7.5) | 1.4% | — | Proxyscotch Project Proxyscotch | 1/5/2022 | 17/6/2026 | The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of sensitive information from the server. | |
| Modificada | Alta (7.8) | 0.58% | — | Samba Cifs-utilsDebian LinuxSuse Caas PlatformSuse Enterprise Storage+15 | 27/4/2022 | 17/6/2026 | In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. | |
| Modificada | Alta (8.1) | 1.4% | — | Articatech WEB Proxy | 25/4/2022 | 17/6/2026 | There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via the filename parameter to /cgi-bin/main.cgi. | |
| Modificada | Alta (7.5) | 3.5% | — | Microsoft YET Another Reverse Proxy | 15/4/2022 | 17/6/2026 | YARP Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 1.7% | — | Finn Podium LayoutFinn Podium Proxy | 6/4/2022 | 17/6/2026 | Podium is a library for building micro frontends. @podium/layout is a module for building a Podium layout server, and @podium/proxy is a module for proxying HTTP requests from a layout server to a podlet server. In @podium/layout prior to version 4.6.110 and @podium/proxy prior to version 4.2.74, an attacker using the… | |
| Modificada | Media (4.8) | 71% | — | Nginxproxymanager Nginx Proxy Manager | 3/4/2022 | 17/6/2026 | jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+24 | 1/4/2022 | 17/6/2026 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. | |
| Modificada | Alta (7.1) | 0.20% | 💥 PoC | Theforeman Smart Proxy Salt | 30/3/2022 | 17/6/2026 | An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the… | |
| Modificada | Media (4) | 0.68% | — | Owasp ZED Attack Proxy | 24/3/2022 | 17/6/2026 | OWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTTPS server. | |
| Modificada | Crítica (9.8) | 1.6% | — | Mitmproxy | 21/3/2022 | 17/6/2026 | mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.4 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a request/response through mitmproxy as part of another… | |
| Modificada | Alta (7.5) | 4.9% | 💥 PoC | Fasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+32 | 11/3/2022 | 17/6/2026 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. | |
| Modificada | Media (5.5) | 4.8% | — | Vmware Spring Cloud GatewayOracle Commerce Guided SearchOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Console+2 | 4/3/2022 | 17/6/2026 | In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates. | |
| Analizada | Crítica (10) | 98% | ⚠ Explotación activa💥 Exploit | Vmware Spring Cloud GatewayOracle Commerce Guided SearchOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Console+6 | 3/3/2022 | 17/6/2026 | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host. | |
| Modificada | Alta (7.5) | 17% | — | HaproxyRedhat Openshift Container PlatformRedhat Software CollectionsRedhat Enterprise Linux+1 | 2/3/2022 | 17/6/2026 | A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability. | |
| Modificada | Media (6.1) | 0.69% | — | Qnap NAS Proxy Server | 25/2/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 )… | |
| Modificada | Media (5.4) | 0.62% | — | Qnap NAS Proxy Server | 25/2/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 )… | |
| Modificada | Alta (8.8) | 4.1% | — | Cyrusimap Cyrus-saslDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+4 | 24/2/2022 | 17/6/2026 | In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. | |
| Modificada | Media (6.1) | 1.1% | — | Fortinet FortiproxyFortinet Fortios | 24/2/2022 | 17/6/2026 | Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0 through 6.4.4; and FortiProxy 1.2.0 through 1.2.9, 2.0.0 through 2.0.1 may allow a remote unauthenticated attacker to perform a reflected… | |
| Modificada | Alta (7.5) | 2.0% | — | IBM Sterling External Authentication ServerIBM Sterling Secure Proxy | 23/2/2022 | 17/6/2026 | IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395. | |
| Modificada | Media (6.5) | 0.58% | — | IBM Sterling External Authentication ServerIBM Sterling Secure Proxy | 23/2/2022 | 17/6/2026 | IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty based GUI in the Secure Zone not properly validating the sizes of the form content and/or HTTP headers submitted. A local attacker positioned inside the Secure Zone… | |
| Modificada | Media (6.5) | 1.0% | — | Envoyproxy Envoy | 22/2/2022 | 17/6/2026 | Envoy is an open source edge and service proxy, designed for cloud-native applications. When a cluster is deleted via Cluster Discovery Service (CDS) all idle connections established to endpoints in that cluster are disconnected. A recursion was introduced in the procedure of disconnecting idle connections that can… | |
| Modificada | Media (6.5) | 0.52% | — | Envoyproxy Envoy | 22/2/2022 | 17/6/2026 | Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does not restrict the set of certificates it accepts from the peer, either as a TLS client or a TLS server, to only those certificates that contain the necessary extendedKeyUsage (id-kp-serverAuth and… |