Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

89 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.2%—Quarkus23/3/202217/6/2026
A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended.
AnalizadaAlta (7.8)1.2%💥 PoCLinux KernelFedoraproject FedoraRedhat Build OF QuarkusRedhat Developer Tools+2618/3/202226/8/2026
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.
ModificadaMedia (5.5)0.53%—Linux KernelFedoraproject FedoraDebian LinuxRedhat Build OF Quarkus+194/3/202217/6/2026
A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808.
ModificadaAlta (7)0.43%—Linux KernelRedhat 3scale API ManagementRedhat Build OF QuarkusRedhat Codeready Linux Builder EUS+283/3/202217/6/2026
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
ModificadaCrítica (9.8)3.1%—Postgresql Jdbc DriverFedoraproject FedoraQuarkusDebian Linux2/2/202217/6/2026
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided…
ModificadaMedia (6.6)1.4%—Oracle Mysql ConnectorsQuarkus19/1/202217/6/2026
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this…
ModificadaAlta (7.5)81%💥 PoCApache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+4214/12/202117/6/2026
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in…
ModificadaMedia (6.5)2.9%—NettyQuarkusNetapp Oncommand Workflow AutomationNetapp Snapcenter+149/12/202117/6/2026
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not…
ModificadaMedia (5.9)7.5%💥 PoCOracle Communications Cloud Native Core ConsoleOracle Communications Cloud Native Core Network Slice Selection FunctionOracle Communications Cloud Native Core PolicyOracle Communications Cloud Native Core Security Edge Protection Proxy+220/10/202117/6/2026
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this…
ModificadaAlta (7.5)6.6%—NettyOracle Banking ApisOracle Banking Digital ExperienceOracle Commerce Guided Search+819/10/202117/6/2026
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input…
ModificadaAlta (7.5)5.9%—NettyQuarkusOracle Banking ApisOracle Banking Digital Experience+1519/10/202117/6/2026
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
ModificadaMedia (5.9)6.3%—Apache KafkaQuarkusOracle Communications BRM - Elastic Charging EngineOracle Communications Cloud Native Core Policy+422/9/202117/6/2026
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected…
ModificadaAlta (7.5)6.7%—JsoupQuarkusOracle Banking Trade FinanceOracle Banking Treasury Management+1218/8/202117/6/2026
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete…
ModificadaMedia (5.3)0.85%—Redhat Wildfly ElytronRedhat Build OF QuarkusRedhat Codeready StudioRedhat Data Grid+95/8/202117/6/2026
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
ModificadaMedia (5.3)2.1%—Eclipse Jakarta Expression LanguageQuarkusOracle Communications Cloud Native Core PolicyOracle Weblogic Server26/5/202117/6/2026
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.
ModificadaMedia (4.3)0.63%—Redhat ResteasyQuarkus26/5/202117/6/2026
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.
ModificadaMedia (4.8)0.53%—Redhat Build OF QuarkusRedhat Data GridRedhat Descision ManagerRedhat Integration Camel K+520/5/202117/6/2026
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
ModificadaCrítica (9.1)8.7%💥 PoCApache MavenQuarkusOracle Financial Services Analytical Applications InfrastructureOracle Goldengate BIG Data AND Application Adapters23/4/202117/6/2026
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the…
ModificadaAlta (7.8)0.54%—GradleQuarkus13/4/202117/6/2026
In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege escalation from an attacker quickly deleting and recreating files in the system…
ModificadaAlta (7.2)1.3%💥 PoCGradleQuarkus13/4/202117/6/2026
In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositories are used to resolve specific dependencies. This feature was…
ModificadaMedia (5.5)0.48%—GradleQuarkus12/4/202117/6/2026
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files accessed through TextResourceFactory are downloaded into the system…
ModificadaMedia (5.9)4.9%—NettyDebian LinuxNetapp Oncommand API ServicesNetapp Oncommand Workflow Automation+1430/3/202117/6/2026
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not…
ModificadaMedia (5.3)1.4%—Redhat ResteasyNetapp Oncommand InsightQuarkusOracle Communications Cloud Native Core Console26/3/202117/6/2026
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this…
ModificadaAlta (7.4)1.3%—Redhat Kubernetes-clientRedhat A-mq OnlineRedhat Build OF QuarkusRedhat Codeready Studio+516/3/202117/6/2026
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system…
ModificadaMedia (5.9)19%—NettyNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationDebian Linux+49/3/202117/6/2026
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is…
Orbitaley — Vulnerabilidades