Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 482 respecto a la semana anterior
Críticas / altas1306▼ 184 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Jenkins Deployer Framework | 27/7/2022 | 17/6/2026 | Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementing form validation, allowing attackers with Item/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. | |
| Modificada | Alta (8.8) | 1.7% | — | Jenkins Deployer Framework | 27/7/2022 | 17/6/2026 | Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the selected service. | |
| Modificada | Media (6.1) | 0.76% | — | Django-rest-framework Django Rest Framework | 23/7/2022 | 17/6/2026 | Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping. | |
| Modificada | Alta (7.5) | 1.1% | — | Oracle Applications Framework | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.9-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Modificada | Media (5.4) | 0.69% | — | Silverstripe Framework | 28/6/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code. | |
| Modificada | Media (5.9) | 0.52% | — | Dradisframework Dradis | 24/6/2022 | 17/6/2026 | Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token. | |
| Modificada | Alta (7.5) | 1.3% | — | Lightbend Play Framework | 2/6/2022 | 17/6/2026 | Play Framework is a web framework for Java and Scala. Verions prior to 2.8.16 are vulnerable to generation of error messages containing sensitive information. Play Framework, when run in dev mode, shows verbose errors for easy debugging, including an exception stack trace. Play does this by configuring its… | |
| Modificada | Alta (7.5) | 1.7% | — | Lightbend Play Framework | 2/6/2022 | 17/6/2026 | Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 through 2.8.15 of Play's forms library, in both the Scala and Java APIs. This can occur when using either the `Form#bindFromRequest` method on a JSON request body or the `Form#bind` method… | |
| Modificada | Media (6.5) | 3.2% | 💥 PoC | Vmware Spring FrameworkOracle Financial Services Crime AND Compliance Management StudioNetapp Cloud Secure AgentNetapp Oncommand Insight | 12/5/2022 | 17/6/2026 | In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | |
| Modificada | Media (5.3) | 2.0% | 💥 PoC | Vmware Spring FrameworkOracle Financial Services Crime AND Compliance Management StudioNetapp Active IQ Unified ManagerNetapp Brocade SAN Navigator+2 | 12/5/2022 | 17/6/2026 | In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | |
| Modificada | Alta (8.8) | 1.7% | — | Pentest Collaboration Framework Project Pentest Collaboration Framework | 11/5/2022 | 17/6/2026 | A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute arbitrary code through /project/PROJECTNAME/reports/. | |
| Modificada | Media (5.5) | 3.2% | — | Microsoft .net Framework | 10/5/2022 | 17/6/2026 | .NET Framework Denial of Service Vulnerability | |
| Modificada | Alta (8.8) | 0.57% | — | Theupdateframework Go-tuf | 5/5/2022 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for updating the metadata files for roles other than the root role. Specifically, checks for rollback attacks are not implemented correctly meaning an attacker can cause clients to install software that… | |
| Modificada | Media (5.4) | 0.52% | — | Oracle Applications Framework | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). Supported versions that are affected are 12.2.6-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Modificada | Media (6.1) | 0.89% | — | Oracle Applications Framework | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Popups). Supported versions that are affected are 12.2.4-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Analizada | Crítica (9.8) | 62% | ⚠ Explotación activa💥 PoC | Oracle Application Development Framework | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (7.5) | 3.6% | — | Microsoft .net Framework | 15/4/2022 | 17/6/2026 | .NET Framework Denial of Service Vulnerability | |
| Modificada | Media (5.3) | 5.7% | 💥 PoC | Vmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Cloud Secure AgentNetapp Metrocluster Tiebreaker+3 | 14/4/2022 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Modificada | Media (6.5) | 36% | — | Vmware Spring Framework | 1/4/2022 | 17/6/2026 | n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition. | |
| Modificada | Alta (7.5) | 4.9% | 💥 PoC | Fasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+32 | 11/3/2022 | 17/6/2026 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. | |
| Modificada | Media (6.5) | 12% | — | Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+25 | 24/1/2022 | 25/8/2026 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version… | |
| Modificada | Alta (7.5) | 3.1% | — | Microsoft .net Framework | 11/1/2022 | 17/6/2026 | .NET Framework Denial of Service Vulnerability | |
| Modificada | Media (4.3) | 0.85% | — | Vmware Spring FrameworkOracle Communications Cloud Native Core ConsoleOracle Communications Cloud Native Core Service Communication Proxy | 10/1/2022 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring… | |
| Modificada | Media (6.6) | 98% | 💥 PoC | Apache Log4jOracle Communications Diameter Signaling RouterOracle Communications Interactive Session RecorderOracle Primavera Gateway+18 | 28/12/2021 | 17/6/2026 | Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting… |