Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.7) | 3.7% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.7) | 3.3% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+16 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (4.8) | 3.3% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+14 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.7) | 3.7% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+16 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.7) | 3.5% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Baja (3.7) | 3.5% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.1) | 3.3% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.4) | 0.75% | — | Theforeman ForemanRedhat Satellite | 1/8/2019 | 17/6/2026 | It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations. | |
| Modificada | Media (6.5) | 1.6% | — | Theforeman Foreman-tasksRedhat Satellite | 31/7/2019 | 17/6/2026 | An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover… | |
| Modificada | Alta (7.4) | 1.5% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 30/7/2019 | 17/6/2026 | All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the… | |
| Modificada | Media (4.8) | 2.3% | — | Oracle JDKOracle JREDebian LinuxOpensuse Leap+9 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple… | |
| Modificada | Baja (3.4) | 2.6% | — | Oracle JDKOracle JREOpensuse LeapHP XP7 Command View+7 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (5.3) | 4.4% | — | Oracle JDKOracle JREDebian LinuxCanonical Ubuntu Linux+9 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Media (5.3) | 4.4% | — | Oracle JDKOracle JRECanonical Ubuntu LinuxOpensuse Leap+9 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Crítica (9.8) | 3.1% | — | Redhat SatelliteRedhat Spacewalk | 2/7/2019 | 17/6/2026 | A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the proxy's filesystem, or can execute arbitrary code in the context… | |
| Modificada | Media (4.3) | 0.57% | — | Redhat SatelliteRedhat Spacewalk | 2/7/2019 | 17/6/2026 | It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum. | |
| Modificada | Alta (8.1) | 12% | 💥 Exploit | Oracle JDKOracle JRERedhat Openshift Container PlatformDebian Linux+11 | 23/4/2019 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability… | |
| Modificada | Alta (8.1) | 11% | 💥 Exploit | Oracle JDKOracle JRECanonical Ubuntu LinuxRedhat Satellite+6 | 23/4/2019 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability… | |
| Modificada | Media (5.9) | 38% | — | Oracle JDKOracle JRERedhat Openshift Container PlatformRedhat Satellite+13 | 23/4/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.5) | 4.4% | — | Oracle JDKOracle JRERedhat Openshift Container PlatformRedhat Satellite+12 | 23/4/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.4) | 6.2% | — | Apache QpidRedhat Jboss AMQ Clients 2Redhat OpenstackRedhat Satellite+6 | 23/4/2019 | 17/6/2026 | While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means… | |
| Modificada | Alta (7.5) | 2.5% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+2 | 19/4/2019 | 17/6/2026 | In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load. | |
| Modificada | Alta (7.8) | 0.68% | — | Redhat Satellite | 15/4/2019 | 17/6/2026 | It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus… | |
| Modificada | Alta (8) | 0.68% | — | Redhat Satellite | 11/4/2019 | 17/6/2026 | A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF… | |
| Modificada | Media (4.9) | 1.8% | — | Theforeman ForemanRedhat Satellite | 9/4/2019 | 17/6/2026 | In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resource" permission can use this flaw to take control over compute… |