Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.99%—Oracle Retail Integration BUS19/4/201817/6/2026
Vulnerability in the Oracle Retail Integration Bus component of Oracle Retail Applications (subcomponent: RIB Kernal(Apache Commons Collections)). The supported version that is affected is 13.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail…
ModificadaAlta (7.5)3.1%—Vmware Spring FrameworkOracle Application Testing SuiteOracle BIG Data DiscoveryOracle Communications Converged Application Server+216/4/201817/6/2026
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to…
ModificadaMedia (5.9)34%💥 ExploitVmware Spring FrameworkOracle Application Testing SuiteOracle BIG Data DiscoveryOracle Communications Converged Application Server+246/4/201817/6/2026
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the…
ModificadaCrítica (9.8)77%💥 PoCVmware Spring FrameworkOracle Application Testing SuiteOracle BIG Data DiscoveryOracle Communications Converged Application Server+246/4/201817/6/2026
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can…
ModificadaMedia (5.6)0.94%—IBM Integration BUS19/1/201817/6/2026
IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before the session times out. IBM X-Force ID: 134164.
ModificadaAlta (8.1)0.81%—IBM Integration BUS20/12/201717/6/2026
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.
ModificadaMedia (5.3)1.2%—IBM Integration BUSIBM Websphere Message Broker4/10/201717/6/2026
IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341.
ModificadaBaja (2.5)0.28%—IBM Websphere Message BrokerIBM Integration BUS5/7/201717/6/2026
IBM WebSphere Message Broker could allow a local user with specialized access to prevent the message broker from starting. IBM X-Force ID: 122033.
ModificadaMedia (5.5)0.32%—IBM Websphere Message BrokerIBM Integration BUS5/7/201717/6/2026
IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777.
ModificadaCrítica (9.8)90%💥 ExploitApache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+7517/4/201717/6/2026
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
ModificadaCrítica (9.1)1.8%—IBM Integration BUSIBM Websphere Message Broker15/2/201717/6/2026
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory…
ModificadaMedia (6.1)0.77%—IBM Integration BUSIBM Websphere Message Broker15/2/201717/6/2026
IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM…
ModificadaMedia (5.9)1.1%—IBM Integration BUS1/2/201717/6/2026
IBM Integration Bus, under non default configurations, could allow a remote user to authenticate without providing valid credentials.
ModificadaBaja (3.3)0.28%—IBM Integration BUSIBM Websphere Message Broker1/2/201717/6/2026
IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.
ModificadaAlta (7.6)2.0%—Oracle Retail Integration BUS21/7/201617/6/2026
Unspecified vulnerability in the Oracle Retail Integration Bus component in Oracle Retail Applications 13.0, 13.1, 13.2, 14.0, 14.1, and 15.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to Install.
ModificadaCrítica (9.8)5.5%—Oracle Retail Integration BUS21/7/201617/6/2026
Unspecified vulnerability in the Oracle Retail Integration Bus component in Oracle Retail Applications 13.0, 13.1, 13.2, 14.0, 14.1, and 15.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Install.
ModificadaAlta (8.8)5.1%—Oracle DocumakerOracle Enterprise Manager OPS CenterOracle Health Sciences Information ManagerOracle Healthcare Master Person Index+721/7/201617/6/2026
Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index…
ModificadaMedia (5.3)1.5%—IBM Integration BUSIBM Websphere Message Broker2/7/201617/6/2026
The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malformed POST request and then reading the Java stack trace.
ModificadaMedia (5.3)1.9%—IBM Integration BUSIBM Websphere Message Broker11/1/201617/6/2026
IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to obtain sensitive information about the HTTP server via unspecified vectors.
ModificadaBaja (3.2)0.33%—IBM Websphere Message BrokerIBM Integration BUS26/10/201517/6/2026
IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.
ModificadaBaja (3.5)0.87%—IBM Integration BUSIBM Websphere Message Broker23/8/201517/6/2026
IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
ModificadaMedia (4.3)1.1%—IBM Websphere Message BrokerIBM Integration BUS28/6/201517/6/2026
IBM WebSphere Message Broker Toolkit 7 before 7007 IF2 and 8 before 8005 IF1 and Integration Toolkit 9 before 9003 IF1 are distributed with MQ client JAR files that support only weak TLS ciphers, which might make it easier for remote attackers to obtain sensitive information by sniffing the network during a connection…
ModificadaMedia (5)1.4%—IBM Integration BUSIBM Websphere Message Broker2/2/201517/6/2026
The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault.
ModificadaMedia (4.3)1.1%—IBM Integration BUS Manufacturing Pack18/9/201417/6/2026
Cross-site scripting (XSS) vulnerability in IBM Integration Bus Manufacturing Pack 1.x before 1.0.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4)1.1%—IBM Websphere Message BrokerIBM Integration BUS18/9/201417/6/2026
The web user interface in IBM WebSphere Message Broker 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.3 allows remote authenticated users to obtain sensitive information by reading the error page.
Orbitaley — Vulnerabilidades