Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.25% | — | Thephpleague Commonmark | 7/3/2026 | 17/6/2026 | league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and the closing >. For example, <script\n> would pass through unfiltered and be rendered as a valid… | |
| Analizada | Baja (2) | 0.39% | — | Getdbt Dbt-common | 6/3/2026 | 17/6/2026 | dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.37.3, a path traversal vulnerability exists in dbt-common's safe_extract() function used when extracting tarball archives. The function uses os.path.commonprefix() to validate that extracted files… | |
| Aplazada | Alta (8.9) | 2.1% | — | Mchange Commons JavaAIMchange C3p0AI | 26/2/2026 | 14/9/2026 | c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a… | |
| Modificada | Alta (8.9) | 1.6% | — | Mchange Commons Java | 25/2/2026 | 17/8/2026 | mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked within a running application. If an attacker can provoke an application to read a… | |
| Analizada | Baja (1.9) | 0.29% | — | Happyfish100 Libfastcommon | 6/2/2026 | 17/6/2026 | A security vulnerability has been detected in happyfish100 libfastcommon up to 1.0.84. Affected by this vulnerability is the function base64_decode of the file src/base64.c. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed publicly… | |
| Aplazada | Crítica (9.8) | 0.56% | — | IBM Common Cryptographic ArchitectureAI | 4/2/2026 | 17/6/2026 | IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system. | |
| Aplazada | Media (4.6) | 0.15% | — | Muntashirakon AppmanagerAIApache Commons CompressAI | 27/1/2026 | 17/6/2026 | Integer Overflow or Wraparound vulnerability in MuntashirAkon AppManager (app/src/main/java/org/apache/commons/compress/archivers/tar modules). This vulnerability is associated with program files TarUtils.Java. This issue affects AppManager: before 4.0.4. | |
| Aplazada | Media (6.3) | 0.54% | — | Backstage Backend-plugin-apiAIBackstage Cli-commonAI | 21/1/2026 | 17/6/2026 | Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functionality used by the backend and command line interface of Backstage. Prior to version 0.1.17, the `resolveSafeChildPath` utility function in `@backstage/backend-plugin-api`, which is used to prevent… | |
| Aplazada | Alta (8.7) | 0.27% | — | Egovframe-common-componentsAI | 19/11/2025 | 14/7/2026 | eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and related file delivery functionality that uses symmetric encryption to protect URL parameters, but exposes an encryption oracle that allows attackers to generate valid ciphertext for chosen values. The… | |
| Aplazada | Media (6.9) | 0.56% | — | Egovframework Egovframe-common-componentsAI | 19/11/2025 | 14/7/2026 | eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vulnerability via the /utl/wed/insertImage.do and /utl/wed/insertImageCk.do image upload endpoints. These controllers accept multipart requests without authentication, pass the uploaded content to a… | |
| Aplazada | Alta (7.5) | 0.43% | — | SAP CommoncryptolibAI | 11/11/2025 | 17/6/2026 | SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 data over the network. This may result in memory corruption followed by an application crash, hence leading to a high impact on availability. There is no impact on confidentiality or integrity. | |
| Aplazada | Media (6.5) | 0.17% | — | Dadevarzan-commonAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dadevarzan Dadevarzan WordPress Common dadevarzan-common allows Stored XSS.This issue affects Dadevarzan WordPress Common: from n/a through <= 2.2.2. | |
| Analizada | Alta (8.4) | 0.42% | — | Libretro-common | 1/9/2025 | 17/6/2026 | Out-of-bounds write in cdfs_open_cue_track in libretro libretro-common latest on all platforms allows remote attackers to execute arbitrary code via a crafted .cue file with a file path exceeding PATH_MAX_LENGTH that is copied using memcpy into a fixed-size buffer. | |
| Modificada | Alta (8.8) | 0.56% | — | Apache Commons Ognl | 18/8/2025 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all versions. When using the API Ognl.getValue, the OGNL engine parses and evaluates the provided expression with powerful capabilities, including… | |
| Modificada | Media (5.3) | 2.5% | — | Apache Commons Lang | 11/7/2025 | 17/6/2026 | Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error… | |
| Aplazada | Media (6.3) | 0.41% | — | Powsybl-commonsAI | 20/6/2025 | 17/6/2026 | PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to version 6.7.2, there is a potential polynomial Regular Expression Denial of Service (ReDoS) vulnerability in the PowSyBl's DataSource mechanism. If successfully exploited, a malicious actor can cause significant CPU… | |
| Modificada | Alta (7.5) | 33% | — | Apache Commons Fileupload | 16/6/2025 | 17/6/2026 | Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue. | |
| Modificada | Alta (8.8) | 1.8% | — | Apache Commons Beanutils | 28/5/2025 | 17/6/2026 | Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean… | |
| Analizada | Media (6.5) | 2.1% | — | Apache Commons Configuration | 9/5/2025 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does not intend… | |
| Aplazada | Media (6.4) | 0.38% | — | Thephpleague CommonmarkAI | 5/5/2025 | 17/6/2026 | league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls into HTML. The league/commonmark library provides configuration options such as… | |
| Aplazada | Media (5.5) | 0.17% | — | Hitachi OPS Center Common ServicesAIHitachi OPS Center OVAAI | 22/4/2025 | 17/6/2026 | Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 before 11.0.4-00. | |
| Aplazada | Alta (7.1) | 0.31% | — | Hitachi OPS Center Common ServicesAIHitachi OPS Center Analyzer Viewpoint OVFAI | 22/4/2025 | 17/6/2026 | Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentials leakage vulnerability.This issue affects Hitachi Ops Center Common Services: from 10.0.0-00 before 11.0.0-04; Hitachi Ops Center Analyzer viewpoint OVF: from 10.0.0-00 before 11.0.0-04. | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Peoplesoft Enterprise CC Common Application Objects | 15/4/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Page and Field Configuration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft… | |
| Analizada | Alta (7.5) | 0.67% | — | Oracle Common Applications | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications.… | |
| Analizada | Alta (8.3) | 0.29% | — | Dell Common Event Enabler | 8/4/2025 | 17/6/2026 | Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Common Anti-Virus Agent (CAVA). An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |