Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 296 respecto a la semana anterior
Críticas / altas1350▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
943 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.7) | 1.8% | — | Nttdata Terasoluna Server Framework FOR Java WEB | 19/6/2016 | 17/6/2026 | NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitrary files, via a crafted pathname. | |
| Modificada | Alta (7.5) | 17% | — | Microsoft Chakra JavascriptMicrosoft JscriptMicrosoft Vbscript | 16/6/2016 | 17/6/2026 | The Microsoft (1) Chakra JavaScript, (2) JScript, and (3) VBScript engines, as used in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption… | |
| Modificada | Crítica (9.1) | 3.9% | — | IBM Java SDKSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITSuse Linux Enterprise Server+2 | 6/6/2016 | 17/6/2026 | The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods. | |
| Modificada | Alta (8.1) | 5.7% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Module FOR Legacy SoftwareNovell Suse Linux Enterprise ServerNovell Suse Manager+9 | 3/6/2016 | 17/6/2026 | The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block,… | |
| Modificada | Alta (8.1) | 4.0% | — | Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node SupplementaryRedhat Enterprise Linux Server+9 | 3/6/2016 | 17/6/2026 | The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController… | |
| Modificada | Media (5.6) | 3.9% | — | Suse Linux Enterprise ServerSuse Linux Enterprise Software Development KITIBM Java SDKRedhat Satellite+9 | 24/5/2016 | 17/6/2026 | Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Analizada | Crítica (10) | 18% | ⚠ Explotación activa | SAP Netweaver Application Server Java | 13/5/2016 | 16/6/2026 | The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack. | |
| Modificada | Media (5.5) | 0.42% | — | Bouncycastle Bc-javaGoogle Android | 18/4/2016 | 17/6/2026 | The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it easier for attackers to defeat a cryptographic protection mechanism and discover an authentication key via a crafted application, aka internal bug 26234568. NOTE: The… | |
| Modificada | Media (6.1) | 1.5% | — | SAP Java AS | 14/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) 15 allows remote attackers to inject arbitrary web script or HTML via the title parameter to webdynpro/resources/sap.com/xapps~xmii~ui~admin~navigation/NavigationApplication, aka SAP Security Note… | |
| Modificada | Media (6.1) | 1.6% | — | Redhat SatelliteRedhat Spacewalk-java | 14/4/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot… | |
| Modificada | Media (5.4) | 1.2% | — | Redhat SatelliteRedhat Spacewalk-java | 14/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811. | |
| Modificada | Alta (7.5) | 7.1% | — | SAP Application Server Java | 8/4/2016 | 17/6/2026 | The Java Startup Framework (aka jstart) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted HTTP request, aka SAP Security Note 2259547. | |
| Modificada | Alta (7.5) | 6.4% | — | SAP Java AS | 8/4/2016 | 17/6/2026 | Internet Communication Manager (aka ICMAN or ICM) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (heap memory corruption and process crash) via a crafted HTTP request, related to the IctParseCookies function, aka SAP Security Note 2256185. | |
| Modificada | Alta (8.8) | 1.3% | — | SAP Netweaver Application Server Java | 8/4/2016 | 17/6/2026 | The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other impact via requests to (1) webcontent/cas/cas_enter.jsp, (2) webcontent/cas/cas_validate.jsp, or… | |
| Analizada | Alta (7.5) | 47% | ⚠ Explotación activa | SAP Netweaver Application Server Java | 7/4/2016 | 17/6/2026 | Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971. | |
| Modificada | Media (6.1) | 1.6% | — | SAP Netweaver Application Server Java | 7/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbitrary web script or HTML via the navigationTarget parameter to irj/servlet/prt/portal/prteventname/XXX/prtroot/com.sapportals.navigation.testComponent.NavigationURLTester, aka SAP Security Note… | |
| Modificada | Crítica (9.1) | 15% | — | SAP Netweaver Application Server Java | 7/4/2016 | 17/6/2026 | XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monitoring~webservice~web/ServerNodesWSService, aka SAP Security Note… | |
| Modificada | Media (5.3) | 2.4% | — | SAP Netweaver Application Server Java | 7/4/2016 | 17/6/2026 | The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to obtain sensitive user information by visiting webdynpro/resources/sap.com/tc~rtc~coll.appl.rtc~wd_chat/Chat#, pressing "Add users", and doing a search, aka SAP Security Note… | |
| Analizada | Media (5.3) | 52% | ⚠ Explotación activa | SAP Netweaver Application Server Java | 16/2/2016 | 17/6/2026 | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846. | |
| Analizada | Crítica (9.8) | 72% | ⚠ Explotación activa | SAP Netweaver Application Server Java | 16/2/2016 | 17/6/2026 | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079. | |
| Modificada | Baja (2.1) | 0.48% | — | IBM Java 2 SDKIBM Java SDKRedhat SatelliteRedhat Enterprise Linux Desktop+5 | 7/12/2015 | 17/6/2026 | IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache. | |
| Modificada | Media (5) | 3.7% | — | Oracle JDKOracle JREOracle Javafx | 22/10/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2015-4906 and CVE-2015-4908. | |
| Modificada | Media (5) | 3.0% | — | Oracle JavafxOracle JDKOracle JRE | 22/10/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2015-4906 and CVE-2015-4916. | |
| Modificada | Media (5) | 3.0% | — | Oracle JavafxOracle JDKOracle JRE | 22/10/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors related to JavaFX, a different vulnerability than CVE-2015-4908 and CVE-2015-4916. | |
| Modificada | Alta (10) | 5.7% | — | Oracle JDKOracle JREOracle Javafx | 16/7/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JavaFX 2.2.80; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. |