Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
943 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 1.3% | — | Dell Bsafe Micro-edition-suiteOracle DatabaseOracle Weblogic Server Proxy Plug-in | 16/12/2020 | 17/6/2026 | Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to modify and corrupt the encrypted data. | |
| Modificada | Alta (7.5) | 2.4% | — | Envoyproxy Envoy | 15/12/2020 | 17/6/2026 | Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500. | |
| Modificada | Alta (8.8) | 0.99% | — | Envoyproxy Envoy | 15/12/2020 | 17/6/2026 | Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters). | |
| Modificada | Media (5.3) | 9.0% | — | Apache HttpclientQuarkusOracle Data IntegratorOracle JD Edwards Enterpriseone Orchestrator+13 | 2/12/2020 | 17/6/2026 | Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. | |
| Analizada | Media (5.3) | 3.2% | — | Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+15 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can… | |
| Analizada | Baja (3.1) | 2.7% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+14 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Baja (3.7) | 2.2% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+14 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Baja (3.1) | 2.5% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+14 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Media (4.2) | 2.2% | — | Oracle OpenjdkOracle JDKOracle JREDebian Linux+15 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Baja (3.7) | 2.3% | — | Oracle OpenjdkOracle JDKOracle JREDebian Linux+12 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Baja (3.7) | 2.3% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+13 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Media (6.5) | 0.58% | — | Fortinet FortiproxyFortinet Fortios | 21/10/2020 | 17/6/2026 | A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an authenticated attacker to obtain sensitive information such as users passwords by connecting to FortiGate CLI and executing the "diag sys ha… | |
| Modificada | Alta (7.5) | 1.1% | — | Envoyproxy Envoy | 1/10/2020 | 17/6/2026 | Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization. | |
| Modificada | Alta (8.3) | 1.3% | — | Envoyproxy Envoy | 1/10/2020 | 17/6/2026 | Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header. | |
| Modificada | Crítica (9.8) | 3.6% | — | Libproxy Project LibproxyFedoraproject FedoraDebian LinuxOpensuse Leap | 30/9/2020 | 17/6/2026 | url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header. | |
| Modificada | Crítica (9.8) | 1.4% | — | Pexip InfinityPexip Reverse Proxy AND Turn Server | 25/9/2020 | 17/6/2026 | Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN. | |
| Modificada | Alta (7.5) | 4.4% | — | Libproxy Project LibproxyDebian LinuxFedoraproject FedoraOpensuse Leap+1 | 9/9/2020 | 17/6/2026 | url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion. | |
| Modificada | Crítica (9.8) | 94% | 💥 Exploit | Articatech WEB Proxy | 12/8/2020 | 17/6/2026 | Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php. | |
| Modificada | Alta (8.8) | 82% | 💥 Exploit | Articatech WEB Proxy | 12/8/2020 | 17/6/2026 | Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform. | |
| Modificada | Media (6.1) | 1.8% | 💥 PoC | Articatech Artica Proxy | 20/7/2020 | 17/6/2026 | An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time request, System Events, Proxy Events, Proxy Objects, and Firewall objects. | |
| Modificada | Alta (7.5) | 2.2% | 💥 PoC | Articatech Artica Proxy | 20/7/2020 | 17/6/2026 | An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields. | |
| Modificada | Alta (8.2) | 3.2% | — | IBM Sterling External Authentication ServerIBM Sterling Secure Proxy | 16/7/2020 | 17/6/2026 | IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or… | |
| Modificada | Media (6.1) | 2.5% | 💥 PoC | Articatech Artica Proxy | 15/7/2020 | 17/6/2026 | An issue was discovered in Artica Proxy before 4.30.000000. Stored XSS exists via the Server Domain Name, Your Email Address, Group Name, MYSQL Server, Database, MYSQL Username, Group Name, and Task Description fields. | |
| Modificada | Baja (3.7) | 3.4% | — | Oracle JDKNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage ManagerNetapp E-series Santricity Unified Manager+5 | 15/7/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability… | |
| Modificada | Media (5.3) | 5.2% | — | Oracle JDKNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage ManagerNetapp E-series Santricity Unified Manager+5 | 15/7/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability… |