Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

86 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.22%—Redhat Openshift-origin-node-util30/6/202217/6/2026
It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.
ModificadaMedia (5.4)0.66%—Originprotocol Origin Website20/4/202217/6/2026
Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to `/presale/join`. User-controlled data is passed with no sanitization to SendGrid and injected into an email that is delivered to the…
ModificadaMedia (5.9)1.2%—Redhat Origin-aggregated-logging11/4/202217/6/2026
A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content. This flaw affects origin-aggregated-logging versions 3.11.
AnalizadaCrítica (9.8)100%⚠ Explotación activaVmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+241/4/202217/6/2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
ModificadaMedia (4.8)0.62%—Origincode Video Gallery25/10/202117/6/2026
The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery before outputting them in attributes, leading to Stored Cross-Site Scripting issues
ModificadaAlta (7.5)1.3%—Sciruby NmatrixUblockorigin Ublock OriginUmatrix Project UmatrixDebian Linux18/7/202117/6/2026
uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).
ModificadaAlta (7.8)0.59%—EA Origin2/11/202017/6/2026
A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user has obtained elevated access, they may be able to take control of the system and perform actions otherwise reserved for high privileged users or system…
ModificadaMedia (5.4)0.64%—EA Origin Client2/11/202017/6/2026
A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to access sensitive data related to the target user’s Origin account, or…
ModificadaAlta (8.8)0.81%—Siteorigin Page Builder28/5/202017/6/2026
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be executed in the…
ModificadaAlta (8.8)0.81%—Siteorigin Page Builder28/5/202017/6/2026
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the…
ModificadaAlta (7.8)0.72%—EA Origin20/2/202017/6/2026
Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different issue than CVE-2019-19247 and CVE-2019-19248. When Origin.exe connects to the named pipe OriginClientService, the privileged service verifies the client's executable file instead…
ModificadaAlta (7.8)0.39%—EA Origin12/12/201917/6/2026
Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).
ModificadaAlta (7.8)0.36%—EA Origin12/12/201917/6/2026
Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2).
ModificadaCrítica (9.8)2.5%—Openshift-origin-controller Project Openshift-origin-controller10/12/201916/6/2026
rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection
ModificadaMedia (5.5)0.31%—Redhat Openshift Origin21/11/201917/6/2026
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly.
ModificadaMedia (6.1)0.66%—Redhat Openshift Origin13/11/201917/6/2026
OpenShift Origin: Improperly validated team names could allow stored XSS attacks
ModificadaMedia (5.5)1.00%—Apache POIOracle Application Testing SuiteOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+2323/10/201917/6/2026
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
ModificadaCrítica (9.8)14%—Oracle Application Testing SuiteOracle Banking Enterprise CollectionsOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+1816/10/201917/6/2026
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and…
ModificadaCrítica (9.8)16%—Softwareag QuartzOracle Apache Batik MapviewerOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+2726/7/201917/6/2026
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
ModificadaAlta (8.8)13%—EA Origin14/6/201917/6/2026
An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arguments into the Origin process and ultimately leverage code execution by loading a backdoored Qt plugin remotely via the platformpluginpath…
ModificadaCrítica (9)2.4%—Ublockorigin Ublock Origin29/4/201917/6/2026
In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service loads a script for execution using XMLHttpRequest or Fetch, and the script origin has an open redirect.
ModificadaAlta (7.8)23%—EA Origin19/4/201917/6/2026
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.
ModificadaAlta (8.1)1.3%—Cisco Media Origination System Suite3/9/201617/6/2026
Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and make arbitrary Platform and Applications Manager (PAM) API calls via unspecified vectors, aka Bug ID CSCuz52110.
ModificadaMedia (5.1)0.37%—Openshift Origin5/8/201617/6/2026
openshift-node in OpenShift Origin 1.1.6 and earlier improperly stores router credentials as envvars in the pod when the --credentials option is used, which allows local users to obtain sensitive private key information by reading the systemd journal.
ModificadaBaja (3.3)0.35%—Redhat OpenshiftRedhat Openshift Origin8/6/201617/6/2026
HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie.