Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.88% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 8/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/autonumber/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 0.88% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 8/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/user/index.php?view=edit&id=. | |
| Modificada | Crítica (9.6) | 1.3% | — | Activitywatch | 7/9/2022 | 17/6/2026 | ActivityWatch open-source automated time tracker. Versions prior to 0.12.0b2 are vulnerable to DNS rebinding attacks. This vulnerability impacts everyone running ActivityWatch and gives the attacker full access to the ActivityWatch REST API. Users should upgrade to v0.12.0b2 or later to receive a patch. As a… | |
| Modificada | Crítica (9.3) | 1.3% | — | Bonn Activity Maps Annotation Tool Project Bonn Activity Maps Annotation Tool | 11/7/2022 | 17/6/2026 | The bonn-activity-maps/bam_annotation_tool repository through 2021-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Analizada | Alta (8.5) | 11% | 💥 Exploit | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected,… | |
| Analizada | Alta (8.5) | 3.4% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected,… | |
| Analizada | Media (6.3) | 5.9% | — | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.5% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+9 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.7% | — | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 14% | 💥 Exploit | XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 4.1% | — | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 98% | ⚠ Explotación activa💥 Exploit | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.5) | 16% | 💥 Exploit | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's… | |
| Analizada | Alta (8.8) | 4.5% | — | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+11 | 23/8/2021 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user is only affected if using the version out of the box with JDK 1.7u21… | |
| Modificada | Alta (8.8) | 77% | 💥 Exploit | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+13 | 28/5/2021 | 17/6/2026 | XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's… | |
| Analizada | Crítica (9.1) | 82% | 💥 Exploit | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to… | |
| Analizada | Crítica (9.8) | 15% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security… | |
| Analizada | Alta (8.6) | 47% | 💥 PoC | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+13 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed… | |
| Analizada | Alta (7.5) | 14% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security… | |
| Analizada | Crítica (9.8) | 14% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… | |
| Analizada | Crítica (9.8) | 76% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… |