Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.7% | — | Smartbear Swagger UIOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Platform+2 | 10/10/2019 | 17/6/2026 | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of… | |
| Modificada | Crítica (9.8) | 4.9% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraRedhat Jboss Enterprise Application Platform+22 | 1/10/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint… | |
| Modificada | Crítica (9.8) | 5.7% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraRedhat Jboss Enterprise Application Platform+24 | 1/10/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service… | |
| Modificada | Crítica (9.8) | 5.0% | — | Fasterxml Jackson-databindFedoraproject FedoraDebian LinuxNetapp Oncommand API Services+13 | 15/9/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540. | |
| Modificada | Crítica (9.8) | 11% | — | Fasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationNetapp Steelstore Cloud Integrated Storage+15 | 15/9/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig. | |
| Modificada | Alta (7.5) | 16% | — | Apache Commons CompressFedoraproject FedoraOracle Banking PaymentsOracle Banking Platform+15 | 30/8/2019 | 17/6/2026 | The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress. | |
| Modificada | Alta (7.3) | 28% | — | Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+56 | 20/8/2019 | 25/8/2026 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | |
| Modificada | Alta (7.5) | 11% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraApache Drill+14 | 30/7/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath. | |
| Modificada | Crítica (9.8) | 8.1% | — | Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+20 | 29/7/2019 | 17/6/2026 | SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution. | |
| Modificada | Crítica (9.8) | 95% | — | XstreamOracle Banking PlatformOracle Business Activity MonitoringOracle Communications Billing AND Revenue Management Elastic Charging Engine+6 | 23/7/2019 | 17/6/2026 | It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of… | |
| Modificada | Media (6.1) | 87% | — | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Crítica (10) | 10% | — | Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Communications Billing AND Revenue Management+8 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 7.5% | — | Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Communications Billing AND Revenue Management+8 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 9.7% | — | Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Business Process Management Suite+16 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 13% | — | Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Business Process Management Suite+21 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization. | |
| Modificada | Alta (7.5) | 2.9% | — | Oracle Banking PlatformOracle Business Process Management SuiteOracle Communications Converged Application ServerOracle Communications Webrtc Session Controller+5 | 17/10/2018 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.… | |
| Modificada | Crítica (9.8) | 4.8% | — | Bouncycastle Bc-javaNetapp Oncommand Workflow AutomationOpensuse LeapOracle API Gateway+20 | 9/7/2018 | 17/6/2026 | Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an… | |
| Modificada | Crítica (9.8) | 38% | — | Fasterxml Jackson-databindDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+17 | 6/2/2018 | 17/6/2026 | A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. | |
| Modificada | Crítica (9.8) | 8.4% | — | Fasterxml Jackson-databindDebian LinuxRedhat Openshift Container PlatformRedhat Satellite+20 | 6/2/2018 | 17/6/2026 | A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting… | |
| Modificada | Media (6.1) | 30% | — | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Crítica (9.8) | 90% | — | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Alta (8.1) | 13% | — | Oracle Banking PlatformOracle PortalApache Struts | 4/7/2016 | 17/6/2026 | ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899. |