Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.22% | — | Redhat Openshift-origin-node-util | 30/6/2022 | 17/6/2026 | It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission. | |
| Modificada | Media (5.4) | 0.66% | — | Originprotocol Origin Website | 20/4/2022 | 17/6/2026 | Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to `/presale/join`. User-controlled data is passed with no sanitization to SendGrid and injected into an email that is delivered to the… | |
| Modificada | Media (5.9) | 1.2% | — | Redhat Origin-aggregated-logging | 11/4/2022 | 17/6/2026 | A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content. This flaw affects origin-aggregated-logging versions 3.11. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Vmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+24 | 1/4/2022 | 17/6/2026 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. | |
| Modificada | Media (4.8) | 0.62% | — | Origincode Video Gallery | 25/10/2021 | 17/6/2026 | The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery before outputting them in attributes, leading to Stored Cross-Site Scripting issues | |
| Modificada | Alta (7.5) | 1.3% | — | Sciruby NmatrixUblockorigin Ublock OriginUmatrix Project UmatrixDebian Linux | 18/7/2021 | 17/6/2026 | uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality). | |
| Modificada | Alta (7.8) | 0.59% | — | EA Origin | 2/11/2020 | 17/6/2026 | A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user has obtained elevated access, they may be able to take control of the system and perform actions otherwise reserved for high privileged users or system… | |
| Modificada | Media (5.4) | 0.64% | — | EA Origin Client | 2/11/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to access sensitive data related to the target user’s Origin account, or… | |
| Modificada | Alta (8.8) | 0.81% | — | Siteorigin Page Builder | 28/5/2020 | 17/6/2026 | An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be executed in the… | |
| Modificada | Alta (8.8) | 0.81% | — | Siteorigin Page Builder | 28/5/2020 | 17/6/2026 | An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the… | |
| Modificada | Alta (7.8) | 0.72% | — | EA Origin | 20/2/2020 | 17/6/2026 | Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different issue than CVE-2019-19247 and CVE-2019-19248. When Origin.exe connects to the named pipe OriginClientService, the privileged service verifies the client's executable file instead… | |
| Modificada | Alta (7.8) | 0.39% | — | EA Origin | 12/12/2019 | 17/6/2026 | Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2). | |
| Modificada | Alta (7.8) | 0.36% | — | EA Origin | 12/12/2019 | 17/6/2026 | Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2). | |
| Modificada | Crítica (9.8) | 2.5% | — | Openshift-origin-controller Project Openshift-origin-controller | 10/12/2019 | 16/6/2026 | rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection | |
| Modificada | Media (5.5) | 0.31% | — | Redhat Openshift Origin | 21/11/2019 | 17/6/2026 | Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly. | |
| Modificada | Media (6.1) | 0.66% | — | Redhat Openshift Origin | 13/11/2019 | 17/6/2026 | OpenShift Origin: Improperly validated team names could allow stored XSS attacks | |
| Modificada | Media (5.5) | 1.00% | — | Apache POIOracle Application Testing SuiteOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+23 | 23/10/2019 | 17/6/2026 | In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing. | |
| Modificada | Crítica (9.8) | 14% | — | Oracle Application Testing SuiteOracle Banking Enterprise CollectionsOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+18 | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and… | |
| Modificada | Crítica (9.8) | 16% | — | Softwareag QuartzOracle Apache Batik MapviewerOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+27 | 26/7/2019 | 17/6/2026 | initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. | |
| Modificada | Alta (8.8) | 13% | — | EA Origin | 14/6/2019 | 17/6/2026 | An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arguments into the Origin process and ultimately leverage code execution by loading a backdoored Qt plugin remotely via the platformpluginpath… | |
| Modificada | Crítica (9) | 2.4% | — | Ublockorigin Ublock Origin | 29/4/2019 | 17/6/2026 | In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service loads a script for execution using XMLHttpRequest or Fetch, and the script origin has an open redirect. | |
| Modificada | Alta (7.8) | 23% | — | EA Origin | 19/4/2019 | 17/6/2026 | The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication. | |
| Modificada | Alta (8.1) | 1.3% | — | Cisco Media Origination System Suite | 3/9/2016 | 17/6/2026 | Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and make arbitrary Platform and Applications Manager (PAM) API calls via unspecified vectors, aka Bug ID CSCuz52110. | |
| Modificada | Media (5.1) | 0.37% | — | Openshift Origin | 5/8/2016 | 17/6/2026 | openshift-node in OpenShift Origin 1.1.6 and earlier improperly stores router credentials as envvars in the pod when the --credentials option is used, which allows local users to obtain sensitive private key information by reading the systemd journal. | |
| Modificada | Baja (3.3) | 0.35% | — | Redhat OpenshiftRedhat Openshift Origin | 8/6/2016 | 17/6/2026 | HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie. |