Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.9) | 72% | 💥 Exploit | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the… | |
| Analizada | Crítica (9.8) | 76% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… | |
| Analizada | Alta (7.5) | 47% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+11 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information.… | |
| Analizada | Crítica (9.1) | 50% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+11 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information.… | |
| Analizada | Alta (7.5) | 78% | 💥 PoC | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+9 | 23/3/2021 | 17/6/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by… | |
| Analizada | Alta (8.8) | 85% | 💥 Exploit | XstreamDebian LinuxNetapp SnapmanagerApache Activemq+11 | 16/11/2020 | 17/6/2026 | XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The… | |
| Modificada | Media (4.3) | 0.92% | — | IBM Security Guardium InsightsIBM Infosphere Guardium Activity Monitor | 9/7/2020 | 17/6/2026 | IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the… | |
| Modificada | Alta (8.8) | 0.46% | — | Drupal Activity | 22/11/2019 | 16/6/2026 | A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal. | |
| Modificada | Media (4.8) | 0.53% | — | Drupal Activity | 21/11/2019 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Activity module 6.x-1.x for Drupal. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (8.1) | 0.71% | — | Incsub Buddypress-activity-plus | 7/10/2019 | 17/6/2026 | The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action. | |
| Modificada | Media (6.1) | 1.0% | — | Pojo Activity LOG | 21/8/2019 | 17/6/2026 | The aryo-activity-log plugin before 2.3.3 for WordPress has XSS. | |
| Modificada | Media (6.1) | 1.1% | — | Pojo Activity LOG | 21/8/2019 | 17/6/2026 | The aryo-activity-log plugin before 2.3.2 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 95% | — | XstreamOracle Banking PlatformOracle Business Activity MonitoringOracle Communications Billing AND Revenue Management Elastic Charging Engine+6 | 23/7/2019 | 17/6/2026 | It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of… | |
| Modificada | Alta (8.8) | 77% | 💥 Exploit | Plainview Activity Monitor Project Plainview Activity Monitor | 26/8/2018 | 17/6/2026 | The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip parameter of a wp-admin/admin.php?page=plainview_activity_monitor&tab=activity_tools request. | |
| Modificada | Crítica (9.8) | 2.4% | — | IBM Security Guardium Database Activity Monitor | 2/5/2018 | 17/6/2026 | IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132624. | |
| Modificada | Media (6.1) | 5.3% | 💥 Exploit | Pojo Activity LOG | 15/3/2018 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary JavaScript or HTML via a title that is not escaped. | |
| Modificada | Media (5.5) | 0.34% | — | IBM Security Guardium Database Activity Monitor | 12/3/2018 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 10 allows local users to obtain sensitive information by reading cached browser data. IBM X-Force ID: 110328. | |
| Modificada | Alta (8.2) | 0.34% | — | IBM Security Guardium Database Activity Monitor | 12/3/2018 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB systems. IBM X-Force ID: 110326. | |
| Modificada | Media (4.4) | 0.29% | — | IBM Security Guardium Database Activity Monitor | 9/2/2018 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not suppose to. IBM X-Force ID: 137765. | |
| Modificada | Media (5.4) | 0.66% | — | Atlassian Activity Streams | 29/1/2018 | 17/6/2026 | Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watch JIRA issues that they do not have access to, although they will not receive… | |
| Modificada | Media (6.1) | 1.7% | — | Dragonbyte-tech Vbactivity Module | 11/1/2018 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the DragonByte Technologies vbActivity module before 3.0.1 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the reason parameter in (1) actions/nominatemedal.php or (2) actions/requestmedal.php. | |
| Modificada | Alta (7.8) | 0.49% | — | IBM Security Guardium Database Activity Monitor | 22/10/2016 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain administrator privileges for command execution via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.8% | — | IBM Security Guardium Database Activity Monitor | 22/10/2016 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP. | |
| Modificada | Baja (3.7) | 1.0% | — | IBM Security Guardium Database Activity Monitor | 22/10/2016 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP. |