Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

446 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.0%—Redhat Jboss Enterprise Application PlatformRedhat Wildfly Core8/11/202323/9/2026
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (5.5)0.16%—Redhat Jboss A-mqRedhat Jboss MiddlewareRedhat Openshift Container Platform27/9/202317/6/2026
A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
ModificadaMedia (5.5)0.25%—Redhat Jboss A-mqRedhat Jboss MiddlewareRedhat Openshift Container Platform27/9/202317/6/2026
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.
ModificadaAlta (7.5)2.7%—Redhat UndertowRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM LinuxoneRedhat Openshift Container Platform FOR Power+327/9/202317/6/2026
A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by…
ModificadaAlta (8.1)1.4%—QuarkusRedhat Build OF OptaplannerRedhat Build OF QuarkusRedhat Decision Manager+820/9/20234/8/2026
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and…
ModificadaAlta (7.5)1.8%—Redhat Build OF QuarkusRedhat Decision ManagerRedhat FuseRedhat Integration Camel K+1214/9/202317/6/2026
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
ModificadaAlta (8.8)1.0%—Redhat Decision ManagerRedhat DroolsRedhat Jboss Middleware Text-only AdvisoriesRedhat Process Automation11/9/202317/6/2026
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
ModificadaMedia (6.5)0.43%—Redhat Build OF QuarkusRedhat Jboss A-mqRedhat KeycloakRedhat Migration Toolkit FOR Runtimes+126/5/202317/6/2026
A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated by the server. If this happens and the…
ModificadaAlta (7.5)0.60%—Redhat Build OF QuarkusRedhat Integration Camel FOR Spring BootRedhat Integration Camel KRedhat Integration Service Registry+623/2/202317/6/2026
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
ModificadaAlta (7.4)0.58%—Redhat Wildfly ElytronRedhat Jboss Enterprise Application Platform13/1/202317/6/2026
wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDigest.isEqual instead. This flaw allows an…
ModificadaAlta (7.5)0.86%—Redhat WildflyRedhat AMQRedhat AMQ OnlineRedhat Integration Camel K+413/9/202217/6/2026
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
ModificadaMedia (4.9)0.89%—Redhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Single Sign-on+51/9/202217/6/2026
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
ModificadaAlta (8.8)5.1%—GNU GzipRedhat Jboss Data GridDebian LinuxTukaani XZ31/8/202217/6/2026
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing…
ModificadaAlta (7.5)1.3%—Redhat Build OF QuarkusRedhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+631/8/202217/6/2026
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
ModificadaAlta (7.5)1.6%—Redhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat UndertowNetapp Cloud Secure Agent+226/8/202217/6/2026
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
ModificadaMedia (4.8)0.56%—Redhat Jboss Core Services Httpd26/8/202217/6/2026
A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this…
ModificadaAlta (7.5)1.7%—Redhat FuseRedhat Integration Camel KRedhat Integration Camel QuarkusRedhat Jboss Enterprise Application Platform+323/8/202217/6/2026
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
ModificadaMedia (5.6)0.22%—Redhat Jboss A-mq16/8/202217/6/2026
A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and information disclosure.
ModificadaAlta (7.5)1.1%—Redhat Integration Camel KRedhat Jboss FuseRedhat Undertow5/8/202217/6/2026
When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementation closes a connection without sending any response to the client/proxy. This behavior results in that a front-end proxy marking the backend worker (application server)…
ModificadaMedia (5.4)0.60%—Redhat Jboss Aerogear1/7/202217/6/2026
Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.
ModificadaAlta (7.5)0.98%—Redhat Jboss Aerogear1/7/202217/6/2026
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generate endless exceptions when those endpoints can't be reached or can slow the…
ModificadaAlta (7.8)0.31%—Redhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat Wildfly Core24/5/202217/6/2026
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions…
ModificadaMedia (5.9)1.3%—Redhat IntegrationRedhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat Undertow+424/5/202217/6/2026
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to…
ModificadaMedia (5.9)1.1%—Redhat FuseRedhat Jboss Enterprise Application PlatformRedhat Openshift Application RuntimesRedhat Single Sign-on+424/5/202217/6/2026
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to…
Orbitaley — Vulnerabilidades