Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 2.9% | 💥 PoC | Json-smart Project Json-smart-v1Json-smart Project Json-smart-v2Oracle Communications Cloud Native Core PolicyOracle OSS Support Tools+3 | 23/2/2021 | 17/6/2026 | An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information. | |
| Modificada | Media (6.5) | 2.2% | — | CkeditorOracle Agile Product Lifecycle ManagementOracle Application ExpressOracle Banking Party Management+6 | 26/1/2021 | 25/8/2026 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin). | |
| Modificada | Media (6.5) | 2.0% | — | CkeditorOracle Agile Product Lifecycle ManagementOracle Application ExpressOracle Financial Services Analytical Applications Infrastructure+3 | 26/1/2021 | 25/8/2026 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin). | |
| Modificada | Crítica (9.1) | 4.4% | — | Apache NutchNetapp Snap Creator Framework | 25/1/2021 | 17/6/2026 | An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows… | |
| Modificada | Alta (7.6) | 0.94% | — | Oracle Siebel Core - Server Framework | 20/1/2021 | 17/6/2026 | Vulnerability in the Siebel Core - Server Framework product of Oracle Siebel CRM (component: Search). Supported versions that are affected are 20.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Core - Server Framework. Successful attacks… | |
| Modificada | Baja (2.4) | 1.3% | — | Oracle Agile Engineering Data ManagementOracle Hyperion Infrastructure TechnologyOracle Siebel UI FrameworkOracle Weblogic Server | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Crítica (9.8) | 75% | 💥 PoC | Oracle CoherenceOracle Utilities Framework | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise… | |
| Modificada | Crítica (9.1) | 6.2% | — | Apache XmlbeansNetapp Oncommand Unified Manager Core PackageNetapp Snap Creator FrameworkNetapp Snapmanager+3 | 14/1/2021 | 17/6/2026 | The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0. | |
| Modificada | Media (5.5) | 1.1% | — | Microsoft BOT Framework Software Development KIT | 12/1/2021 | 17/6/2026 | Bot Framework SDK Information Disclosure Vulnerability | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Getlaminas Laminas-httpZend Framework | 4/1/2021 | 17/6/2026 | Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the… | |
| Modificada | Alta (8.1) | 7.2% | 💥 PoC | Bouncycastle Bc-javaApache KarafOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+16 | 18/12/2020 | 17/6/2026 | An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different. | |
| Modificada | Baja (2.7) | 0.97% | — | Lightbend Play Framework | 3/12/2020 | 17/6/2026 | An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version prior to 2.8.0 that used the Play Java API to serialize classes with protected or private fields to JSON. | |
| Modificada | Alta (7.5) | 17% | — | Fasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationNetapp Service Level Manager+35 | 3/12/2020 | 25/8/2026 | A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity. | |
| Modificada | Media (6.5) | 1.1% | — | Bitrix24 Bitrix Framework | 2/12/2020 | 17/6/2026 | An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a remote user to enumerate users in the administrator group. This also allows brute-force attacks on… | |
| Modificada | Media (4.8) | 8.3% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkOracle Blockchain Platform+13 | 28/11/2020 | 17/6/2026 | In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely… | |
| Modificada | Media (6.1) | 41% | — | Apache CXFNetapp Snap Creator FrameworkNetapp Vasa Provider FOR Clustered Data OntapOracle Business Intelligence+2 | 12/11/2020 | 17/6/2026 | By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all… | |
| Modificada | Alta (7.5) | 1.4% | — | Lightbend Play Framework | 6/11/2020 | 17/6/2026 | An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON structure sent to a valid POST endpoint (that may or may not expect JSON payloads) causes a StackOverflowError and Denial of Service. | |
| Modificada | Alta (7.5) | 1.4% | — | Lightbend Play Framework | 6/11/2020 | 17/6/2026 | In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents. | |
| Modificada | Alta (7.5) | 1.4% | — | Lightbend Play Framework | 6/11/2020 | 17/6/2026 | In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input. | |
| Modificada | Alta (7) | 4.4% | — | Eclipse JettyNetapp Snap Creator FrameworkNetapp SnapcenterNetapp Vasa Provider+14 | 23/10/2020 | 17/6/2026 | In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared… | |
| Modificada | Crítica (9.1) | 2.0% | — | Microchip Advanced Software Framework 4 | 22/10/2020 | 17/6/2026 | Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow. | |
| Modificada | Media (5.4) | 0.77% | — | Oracle Utilities Framework | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.2.0.0.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 - 4.3.0.6.0, 4.4.0.0.0 and 4.4.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network… | |
| Modificada | Media (4.7) | 1.2% | — | Oracle Applications Framework | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Popup windows). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications… | |
| Modificada | Media (6.1) | 0.83% | — | SAP Netweaver Composite Application Framework | 20/10/2020 | 17/6/2026 | There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50. An unauthenticated attacker can trick an unsuspecting authenticated user to click on a malicious link. The end users browser has no way to know that the script should not… | |
| Modificada | Media (5.5) | 3.3% | — | Microsoft .net Framework | 16/10/2020 | 17/6/2026 | <p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.</p> <p>To exploit the vulnerability, an authenticated attacker would need to run a specially… |