Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
523 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.2) | 0.24% | — | Redhat Single Sign ONAIRedhat Jboss Enterprise Application PlatformAIRedhat Oidc ClientAI | 9/12/2024 | 4/8/2026 | A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a… | |
| Analizada | Media (6.1) | 0.46% | — | Redhat Codeready StudioRedhat Jboss Enterprise Application PlatformRedhat Openstack PlatformRedhat Single Sign-on+1 | 7/11/2024 | 17/6/2026 | A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS)… | |
| Modificada | Alta (7.3) | 0.68% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform | 22/10/2024 | 19/8/2026 | A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against the server. | |
| Modificada | Alta (7.5) | 2.6% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Build OF KeycloakRedhat Data Grid+5 | 21/8/2024 | 24/9/2026 | A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder… | |
| Analizada | Media (5.4) | 0.17% | — | Bosscms | 10/6/2024 | 17/6/2026 | BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code." | |
| Modificada | Media (4.3) | 0.38% | — | Buddyboss Platform | 5/6/2024 | 17/6/2026 | The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request | |
| Analizada | Media (5.3) | 0.43% | — | Buddyboss | 4/6/2024 | 17/6/2026 | The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID included in the request | |
| Analizada | Alta (7.1) | 0.37% | — | Bosscms | 25/4/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration. | |
| Modificada | Media (6.5) | 0.79% | — | JberetRedhat Jboss Enterprise Application Platform | 25/4/2024 | 17/6/2026 | A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection. | |
| Aplazada | Crítica (9.8) | 0.70% | — | Buddyboss ThemeAI | 24/4/2024 | 17/6/2026 | Improper Authentication vulnerability in BUDDYBOSS DMCC BuddyBoss Theme allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyBoss Theme: from n/a through 2.4.60. | |
| Analizada | Alta (8.1) | 1.6% | — | Redhat Build OF KeycloakRedhat Jboss Middleware Text-only AdvisoriesRedhat KeycloakRedhat Migration Toolkit FOR Applications+6 | 17/4/2024 | 4/8/2026 | A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that… | |
| Aplazada | Alta (7.3) | 0.78% | — | Jboss EAPAI | 9/4/2024 | 17/6/2026 | A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability. | |
| Modificada | Media (6.1) | 22% | 💥 Exploit | Iboss Secure WEB Gateway | 6/4/2024 | 17/6/2026 | A vulnerability has been found in iboss Secure Web Gateway up to 10.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login of the component Login Portal. The manipulation of the argument redirectUrl leads to cross site scripting. The attack can be launched… | |
| Modificada | Alta (7.5) | 4.6% | — | Netapp Active IQ Unified ManagerNetapp Oncommand Workflow AutomationRedhat FuseRedhat Integration Camel FOR Spring Boot+5 | 19/2/2024 | 2/10/2026 | A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits… | |
| Modificada | Alta (7.5) | 0.72% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack | 6/2/2024 | 17/6/2026 | An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server. | |
| Modificada | Alta (8.8) | 0.24% | — | Elisebosse Frontpage Manager | 31/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Elise Bosse Frontpage Manager.This issue affects Frontpage Manager: from n/a through 1.3. | |
| Modificada | Alta (7.8) | 0.31% | — | Bosscms | 30/1/2024 | 17/6/2026 | Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component. | |
| Modificada | Alta (7.5) | 1.0% | — | Redhat Jboss Enterprise Application Platform | 27/12/2023 | 17/6/2026 | A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service. | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Baja (2.7) | 0.54% | — | Redhat Data GridRedhat Jboss Data GridInfinispan | 18/12/2023 | 17/6/2026 | A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration. | |
| Modificada | Media (6.5) | 1.1% | — | Redhat Data GridRedhat Jboss Data GridInfinispan | 18/12/2023 | 17/6/2026 | A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service. | |
| Modificada | Media (6.5) | 0.72% | — | Redhat Data GridRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformInfinispan | 18/12/2023 | 17/6/2026 | A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions. | |
| Modificada | Media (6.5) | 0.80% | — | Redhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Data GridInfinispan | 18/12/2023 | 17/6/2026 | A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions. | |
| Modificada | Alta (7.5) | 1.0% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat Undertow | 12/12/2023 | 4/8/2026 | A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss… | |
| Modificada | Media (6.5) | 1.0% | — | Redhat Jboss Enterprise Application PlatformRedhat Wildfly Core | 8/11/2023 | 23/9/2026 | A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system. |