Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1353 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+54 | 4/10/2017 | 25/8/2026 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP… | |
| Modificada | Alta (7.5) | 54% | 💥 Exploit | Nodejs Node.js | 28/9/2017 | 17/6/2026 | Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules. | |
| Modificada | Alta (8.8) | 3.5% | — | Ovirt-node | 26/9/2017 | 17/6/2026 | ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate attackers to execute arbitrary commands via a ;… | |
| Modificada | Media (6.1) | 1.3% | — | Nodebb | 21/9/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript: or (2) data: URLs. | |
| Modificada | Media (6.5) | 5.0% | — | Nodejs Node.jsUronode URO NodeDebian Linux | 20/9/2017 | 17/6/2026 | node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption). | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatNetapp 7-mode Transition ToolNetapp Oncommand BalanceNetapp Oncommand Shift+18 | 19/9/2017 | 6/8/2026 | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed… | |
| Modificada | Media (5.5) | 0.38% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+3 | 25/7/2017 | 17/6/2026 | The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack. | |
| Modificada | Alta (7.5) | 5.4% | 💥 PoC | Nodejs Node.js | 25/7/2017 | 17/6/2026 | Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default… | |
| Modificada | Alta (7.5) | 9.1% | — | Fedoraproject FedoraSuse Linux Enterprise DebuginfoOpensuse LeapOpensuse+16 | 21/7/2017 | 17/6/2026 | The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to… | |
| Modificada | Alta (7.5) | 6.1% | — | Fedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise ServerSuse Manager+14 | 21/7/2017 | 17/6/2026 | The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet. | |
| Modificada | Alta (7.5) | 8.8% | 💥 PoC | Fedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+4 | 21/7/2017 | 17/6/2026 | ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation. | |
| Modificada | Alta (7.5) | 6.5% | — | Fedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise ServerSuse Manager+9 | 21/7/2017 | 17/6/2026 | The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands. | |
| Modificada | Alta (7.5) | 3.3% | — | C-aresC-ares Project C-aresNodejs Node.js | 7/7/2017 | 17/6/2026 | The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way. | |
| Modificada | Alta (7.8) | 0.37% | — | Redhat Storage ConsoleRedhat Storage Console Node | 27/6/2017 | 17/6/2026 | rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain the password as cleartext. | |
| Modificada | Crítica (9.8) | 5.3% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 8/6/2017 | 17/6/2026 | SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 3.2% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 8/6/2017 | 17/6/2026 | 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to read the default Access Control Instructions. | |
| Modificada | Crítica (9.8) | 3.1% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 8/6/2017 | 17/6/2026 | 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords. | |
| Modificada | Alta (7.5) | 2.4% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 8/6/2017 | 17/6/2026 | 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to infer the existence of RDN component objects. | |
| Modificada | Alta (7.5) | 1.7% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 8/6/2017 | 17/6/2026 | mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled. | |
| Modificada | Crítica (9.8) | 5.8% | — | ZlibOpensuse LeapOpensuseDebian Linux+20 | 23/5/2017 | 17/6/2026 | The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation. | |
| Modificada | Alta (8.8) | 5.2% | — | ZlibOpensuse LeapOpensuseDebian Linux+15 | 23/5/2017 | 14/7/2026 | The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers. | |
| Modificada | Crítica (9.8) | 7.5% | — | ZlibOpensuse LeapOpensuseDebian Linux+35 | 23/5/2017 | 14/7/2026 | inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | |
| Modificada | Alta (8.8) | 4.8% | — | BoostZlibOpensuse LeapOpensuse+16 | 23/5/2017 | 14/7/2026 | inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | |
| Modificada | Crítica (9.8) | 2.5% | — | Keycloak-nodejs-auth-utils | 12/5/2017 | 17/6/2026 | It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks. | |
| Modificada | Media (5.9) | 14% | — | OpensslNodejs Node.js | 4/5/2017 | 17/6/2026 | There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine… |