Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.7% | 💥 PoC | Owasp Enterprise Security APIOracle Weblogic ServerNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation | 27/4/2022 | 17/6/2026 | ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a potential for a cross-site scripting vulnerability in ESAPI caused by a incorrect regular expression for "onsiteURL" in the **antisamy-esapi.xml** configuration file that can… | |
| Modificada | Crítica (9.8) | 2.8% | 💥 PoC | Owasp Enterprise Security APIOracle Weblogic ServerNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation | 25/4/2022 | 17/6/2026 | ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a child of the specified parent… | |
| Modificada | Media (6.1) | 1.3% | 💥 PoC | Antisamy Project AntisamyOracle Enterprise Manager Base PlatformOracle Weblogic Server | 21/4/2022 | 17/6/2026 | OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367. | |
| Modificada | Media (6.1) | 0.88% | — | Oracle Weblogic Server | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.… | |
| Modificada | Alta (7.5) | 1.4% | — | Oracle Weblogic Server | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3/IIOP to compromise Oracle WebLogic Server.… | |
| Modificada | Media (6.1) | 0.56% | — | Forestblog Project Forestblog | 16/4/2022 | 17/6/2026 | ForestBlog through 2022-02-16 allows admin/profile/save userAvatar XSS during addition of a user avatar. | |
| Modificada | Alta (7.5) | 2.1% | — | Nekohtml Project NekohtmlOracle Weblogic Server | 11/4/2022 | 17/6/2026 | org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to upgrade to `>= 1.9.22.noko2`. Note: The upstream library `org.cyberneko.html` is no longer… | |
| Modificada | Crítica (9.8) | 1.1% | — | Moguit Mogu Blog CMS | 8/4/2022 | 17/6/2026 | mogu_blog_cms 5.2 suffers from upload arbitrary files without any limitation. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Modificada | Crítica (9.8) | 2.6% | — | Nttr GOO Blog | 29/3/2022 | 17/6/2026 | NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary code via a crafted HTTP request. | |
| Modificada | Alta (7.5) | 4.9% | 💥 PoC | Fasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+32 | 11/3/2022 | 17/6/2026 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. | |
| Modificada | Media (6.1) | 0.91% | — | Appleple A-blog CMS | 24/2/2022 | 17/6/2026 | Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated… | |
| Modificada | Media (6.1) | 0.77% | — | Appleple A-blog CMS | 24/2/2022 | 17/6/2026 | Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated… | |
| Modificada | Media (6.5) | 1.1% | — | Appleple A-blog CMS | 24/2/2022 | 17/6/2026 | Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and… | |
| Modificada | Crítica (9.8) | 1.5% | — | Appleple A-blog CMS | 24/2/2022 | 17/6/2026 | Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to Ver.2.10.43, and Ver.2.11.x series versions prior to Ver.2.11.41 allows a remote unauthenticated attacker to bypass authentication under… | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Alta (8.8) | 9.9% | 💥 Exploit | Blog Project Blog | 8/2/2022 | 17/6/2026 | m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` have not been checked properly. Although PHP issued warnings and the upload function returned `false`, the original file (that could contain a malicious payload) was kept on the disk. Users are… | |
| Modificada | Media (6.5) | 0.67% | — | Oneblog Project Oneblog | 25/1/2022 | 17/6/2026 | OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators beyond their authority. | |
| Modificada | Media (6.1) | 0.59% | — | Forestblog Project Forestblog | 25/1/2022 | 17/6/2026 | A problem was found in ForestBlog, as of 2021-12-29, there is a XSS vulnerability that can be injected through the nickname input box. | |
| Modificada | Crítica (9.8) | 1.2% | — | Forestblog Project Forestblog | 25/1/2022 | 17/6/2026 | In ForestBlog, as of 2021-12-28, File upload can bypass verification. | |
| Modificada | Media (6.5) | 12% | — | Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+25 | 24/1/2022 | 25/8/2026 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version… | |
| Modificada | Media (4.3) | 0.36% | — | Mblog Project Mblog | 20/1/2022 | 17/6/2026 | In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted. | |
| Modificada | Media (5.4) | 0.50% | — | Oneblog Project Oneblog | 19/1/2022 | 17/6/2026 | A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in the background. | |
| Modificada | Media (6.1) | 0.95% | — | Oracle Weblogic Server | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (7.5) | 93% | 💥 Exploit | Oracle Weblogic Server | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… |