Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.9% | — | Oracle GraalvmOracle JDKOracle JREFedoraproject Fedora+11 | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows… | |
| Modificada | Baja (3.7) | 1.6% | — | Oracle GraalvmOracle JDKOracle JREFedoraproject Fedora+11 | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability… | |
| Modificada | Baja (3.7) | 2.7% | — | Oracle GraalvmOracle JDKOracle JREFedoraproject Fedora+11 | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability… | |
| Modificada | Alta (7.5) | 0.76% | — | Mozilla Network Security Services | 14/10/2022 | 17/6/2026 | A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash. | |
| Modificada | Media (6.1) | 0.55% | — | SAP Data Services | 11/10/2022 | 17/6/2026 | SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it will lead to a Cross-Site Scripting vulnerability. The attacker would have to log in to the management console to perform such as an attack, only few of the pages are vulnerable in… | |
| Modificada | Media (6.7) | 0.22% | — | Avaya Aura Application Enablement Services | 6/10/2022 | 17/6/2026 | A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services versions 8.0.0.0 through 8.1.3.4 and… | |
| Modificada | Alta (8.1) | 1.9% | 💥 PoC | Amazon WEB Services Redshift Java Database Connectivity Driver | 29/9/2022 | 17/6/2026 | In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name. | |
| Modificada | Alta (7.5) | 0.87% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAKIBM Robotic Process Automation FOR Services | 29/9/2022 | 17/6/2026 | IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422. | |
| Modificada | Alta (8.8) | 0.39% | — | Ydesignservices YDS Support Ticket System | 23/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in YDS Support Ticket System plugin <= 1.0 at WordPress. | |
| Modificada | Media (6.1) | 1.5% | — | JsoupNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCINetapp Oncommand Workflow Automation | 29/8/2022 | 17/6/2026 | jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks`… | |
| Modificada | Media (4.8) | 0.56% | — | Redhat Jboss Core Services Httpd | 26/8/2022 | 17/6/2026 | A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this… | |
| Modificada | Media (5.5) | 0.29% | — | Linux KernelIBM Spectrum Copy Data ManagementIBM Spectrum Protect PlusDebian Linux+19 | 26/8/2022 | 17/6/2026 | A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. | |
| Modificada | Alta (7.5) | 1.6% | — | Dogtagpki Network Security Services FOR JavaRedhat Enterprise LinuxDebian Linux | 24/8/2022 | 17/6/2026 | A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service. | |
| Modificada | Media (6.5) | 1.5% | 💥 PoC | Redhat LibvirtCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+10 | 23/8/2022 | 17/6/2026 | A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged… | |
| Modificada | Alta (7.8) | 0.39% | — | LibarchiveFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+10 | 23/8/2022 | 17/6/2026 | An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may… | |
| Modificada | Alta (7.8) | 0.39% | — | LibarchiveFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+9 | 23/8/2022 | 17/6/2026 | An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL… | |
| Modificada | Media (4.4) | 0.20% | — | Intel Server Platform Services Firmware | 18/8/2022 | 17/6/2026 | Incomplete cleanup in a firmware subsystem for Intel(R) SPS before versions SPS_E3_04.08.04.330.0 and SPS_E3_04.01.04.530.0 may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Alta (8.4) | 0.11% | — | Google Play Services Software Development KIT | 12/8/2022 | 17/6/2026 | Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application affected, this bug will let the attacker, gain the access to all… | |
| Modificada | Media (6.5) | 0.61% | — | IBM Spectrum Scale Data Access Services | 10/8/2022 | 17/6/2026 | IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016. | |
| Modificada | Media (4.9) | 0.95% | — | Cisco Identity Services Engine | 10/8/2022 | 17/6/2026 | A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API output. An attacker could exploit this vulnerability by… | |
| Modificada | Crítica (9.8) | 19% | 💥 PoC | ZlibFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+14 | 5/8/2022 | 14/7/2026 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the… | |
| Modificada | Alta (7.8) | 0.57% | — | Trendmicro Apex ONETrendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security Services | 30/7/2022 | 17/6/2026 | A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents could allow a local attacker to escalate privileges on affected installations. The resolution for this issue has been deployed automatically via ActiveUpdate to customers in an updated Spyware… | |
| Modificada | Crítica (9.8) | 0.30% | — | Google Play Services Software Development KIT | 29/7/2022 | 17/6/2026 | Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play services is trusted by the SDK for devices that are non-GMS. We recommend upgrading the SDK past the 2022-05-03 release. | |
| Modificada | Alta (7.8) | 0.22% | — | Aveva Batch ManagementAveva Enterprise Data ManagementAveva Manufacturing Execution SystemAveva Mobile Operator+3 | 27/7/2022 | 17/6/2026 | AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path. | |
| Modificada | Media (5.9) | 0.52% | — | Oracle Financial Services Revenue Management AND Billing | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 2.9.0.0.0, 2.9.0.1.0, 3.0.0.0.0-3.2.0.0.0 and 4.0.0.0.0. Difficult to exploit vulnerability allows low privileged… |