Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)8.4%💥 PoCNetapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+416/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
ModificadaAlta (8.1)4.1%—Netapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+406/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
AnalizadaAlta (8.1)13%💥 PoCFasterxml Jackson-databindDebian LinuxNetapp Service Level ManagerOracle Agile Product Lifecycle Management+3627/12/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
ModificadaAlta (8.1)7.8%—Fasterxml Jackson-databindNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+2217/12/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
ModificadaAlta (8.1)6.3%—Fasterxml Jackson-databindNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+2117/12/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
ModificadaAlta (7.5)17%—Fasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationNetapp Service Level Manager+353/12/202025/8/2026
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
ModificadaAlta (7.5)8.0%—Apache ANTGradleFedoraproject FedoraOracle Agile Engineering Data Management+331/10/202017/6/2026
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still…
ModificadaMedia (6.5)11%💥 PoCVmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRMOracle Communications Design Studio+3419/9/202017/6/2026
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
ModificadaAlta (8.1)7.3%💥 PoCFasterxml Jackson-databindOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Autovue FOR Agile Product Lifecycle Management+2217/9/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
ModificadaAlta (8.1)7.6%💥 PoCFasterxml Jackson-databindNetapp Active IQ Unified ManagerOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+2125/8/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
ModificadaCrítica (9.8)7.3%—Dom4j Project Dom4jOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Banking Platform+341/5/202025/8/2026
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
ModificadaBaja (3.7)8.1%💥 PoCApache Log4jOracle Communications Application Session ControllerOracle Communications Billing AND Revenue ManagementOracle Communications Eagle FTP Table Base Retrieval+4227/4/202017/6/2026
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaMedia (6.1)2.5%—Eclipse MojarraOracle Mojarra Javaserver FacesOracle Application Testing SuiteOracle Banking Enterprise Product Manufacturing+192/10/201917/6/2026
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
ModificadaMedia (6.5)3.8%—Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jOracle Application Performance Management+1418/9/201917/6/2026
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.
ModificadaMedia (6.5)1.7%—Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jMcafee Threat Intelligence Exchange Server+1218/9/201917/6/2026
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
ModificadaAlta (7.3)28%—Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+5620/8/201925/8/2026
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
ModificadaCrítica (9.8)95%—XstreamOracle Banking PlatformOracle Business Activity MonitoringOracle Communications Billing AND Revenue Management Elastic Charging Engine+623/7/201917/6/2026
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of…
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaAlta (7.5)9.2%—Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Communications BRM - Elastic Charging EngineOracle Communications Converged Application Server - Service Controller+3618/10/201825/8/2026
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an…
ModificadaAlta (7.5)3.2%—Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Network Integrity+2425/6/201817/6/2026
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not…
ModificadaMedia (5.9)2.7%—Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Diameter Signaling Router+2925/6/201825/8/2026
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a…
ModificadaMedia (6.5)3.0%—Vmware Spring FrameworkRedhat OpenshiftOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+2611/5/201817/6/2026
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that…
ModificadaMedia (5.4)0.89%—Oracle Communications Unified Inventory Management18/1/201817/6/2026
Vulnerability in the Oracle Communications Unified Inventory Management component of Oracle Communications Applications (subcomponent: Portal). Supported versions that are affected are 7.2.4.2.x and 7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (6.3)1.1%—Oracle Communications Unified Inventory Management18/1/201817/6/2026
Vulnerability in the Oracle Communications Unified Inventory Management component of Oracle Communications Applications (subcomponent: Portal). Supported versions that are affected are 7.2.4.2.x and 7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
Orbitaley — Vulnerabilidades