Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.17% | — | Realtycandy IDX Broker ExtendedAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RealtyCandy.com RealtyCandy IDX Broker Extended realtycandy-idx-broker-extended allows Stored XSS.This issue affects RealtyCandy IDX Broker Extended: from n/a through <= 1.5.1. | |
| Modificada | Media (5.4) | 0.26% | — | Idxbroker Impress FOR IDX Broker | 17/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IDX Broker IMPress for IDX Broker idx-broker-platinum allows Stored XSS.This issue affects IMPress for IDX Broker: from n/a through <= 3.2.2. | |
| Aplazada | Media (4.3) | 0.36% | — | SAS BrokerAI | 26/6/2024 | 17/6/2026 | Buffer Overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or obtain sensitive information via crafted payload to the '_debug' parameter. | |
| Aplazada | Alta (7.5) | 0.54% | — | Rmqtt BrokerAI | 12/6/2024 | 17/6/2026 | RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can exhaust system memory and crash the daemon by establishing and maintaining a vast number of long-lived malicious publish/subscribe sessions. | |
| Modificada | Media (4.8) | 0.41% | — | Wso2 API ManagerWso2 API Manager AnalyticsWso2 API MicrogatewayWso2 Data Analytics Server+5 | 18/12/2023 | 17/6/2026 | Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console. | |
| Modificada | Media (4.8) | 0.39% | — | Goldbroker Live Gold Price & Silver Price Charts Widgets | 14/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GoldBroker.Com Live Gold Price & Silver Price Charts Widgets plugin <= 2.4 versions. | |
| Modificada | Media (4.4) | 1.4% | — | Microsoft Identity Linux Broker | 12/9/2023 | 17/6/2026 | Microsoft Identity Linux Broker Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 0.64% | — | Filebroker Project Filebroker | 7/1/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in peel filebroker and classified as critical. Affected by this issue is the function select_transfer_status_desc of the file lib/common.rb. The manipulation leads to sql injection. The name of the patch is 91097e26a6c84d3208a351afaa52e0f62e5853ef. It is… | |
| Modificada | Media (5.3) | 3.1% | — | Redhat AMQ BrokerApache Artemis | 24/8/2022 | 17/6/2026 | A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted messages. The highest threat from this… | |
| Modificada | Media (4.3) | 0.68% | — | Redhat AMQ Broker | 23/8/2022 | 17/6/2026 | A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality as this flaw means some role bindings are… | |
| Modificada | Alta (7.8) | 0.22% | — | Automationbroker APB | 16/8/2022 | 17/6/2026 | A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all users sudoer permissions allowing an unauthorized user with access to the running container the ability to escalate their own privileges. The highest threat from this vulnerability is to data… | |
| Modificada | Media (4.9) | 1.6% | — | Snyk Broker | 25/7/2022 | 17/6/2026 | This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal. | |
| Modificada | Alta (7.5) | 2.3% | — | Dbus-broker Project Dbus-broker | 17/7/2022 | 17/6/2026 | An issue was discovered in dbus-broker before 31. Multiple NULL pointer dereferences can be found when supplying a malformed XML config file. | |
| Modificada | Alta (7.5) | 2.3% | — | Dbus-broker Project Dbus-broker | 17/7/2022 | 17/6/2026 | An issue was discovered in dbus-broker before 31. It depends on c-uitl/c-shquote to parse the DBus service's Exec line. c-shquote contains a stack-based buffer over-read if a malicious Exec line is supplied. | |
| Modificada | Alta (8.8) | 0.85% | — | Redhat AMQ Broker | 21/6/2022 | 17/6/2026 | A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where the AMQ Operator is deployed has access to clusterwide edit rights by checking the secrets. The service account used for building the Operator gives more permission than… | |
| Modificada | Alta (7.5) | 12% | — | Google GsonDebian LinuxNetapp Active IQ Unified ManagerOracle Financial Services Crime AND Compliance Management Studio+2 | 1/5/2022 | 17/6/2026 | The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. | |
| Modificada | Media (4.9) | 1.3% | — | Leostream Connection Broker | 18/1/2022 | 17/6/2026 | Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link. | |
| Modificada | Alta (7.2) | 0.96% | — | Leostream Connection Broker | 18/1/2022 | 17/6/2026 | Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code. | |
| Modificada | Media (6.6) | 98% | 💥 PoC | Apache Log4jOracle Communications Diameter Signaling RouterOracle Communications Interactive Session RecorderOracle Primavera Gateway+18 | 28/12/2021 | 17/6/2026 | Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting… | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modificada | Alta (7.4) | 50% | 💥 PoC | OpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+28 | 24/8/2021 | 17/6/2026 | ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a… | |
| Modificada | Crítica (9.8) | 88% | — | OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+27 | 24/8/2021 | 17/6/2026 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the… | |
| Modificada | Media (6.1) | 1.1% | — | Leostream Connection Broker | 6/8/2021 | 17/6/2026 | LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modificada | Alta (7.5) | 1.1% | — | Emqx EMQ X Broker | 8/6/2021 | 17/6/2026 | EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of untrusted inputs. These inputs cause the message broker to consume large amounts of memory, resulting in the application being terminated by the operating system. |