Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

149 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)90%💥 ExploitApache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+7517/4/201717/6/2026
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
AnalizadaCrítica (9.8)93%⚠ Explotación activa💥 ExploitApache AuroraApache ShiroRedhat FuseRedhat Jboss Middleware Text-only Advisories7/6/201617/6/2026
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
ModificadaAlta (7.3)2.9%—Fuseiso Project FuseisoDebian LinuxFedoraproject Fedora30/3/201617/6/2026
Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long pathname in an ISO file.
ModificadaAlta (7.3)1.8%—Fedoraproject FedoraFuseiso Project Fuseiso30/3/201617/6/2026
Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF block size in an ISO file, leading to a heap-based buffer overflow.
ModificadaAlta (7.8)0.37%—Debian Fuse26/1/201617/6/2026
An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world-writable permissions for the /dev/cuse character device, which allows local users to gain privileges via a character device in /dev, related to an ioctl.
ModificadaMedia (6)1.5%—Redhat Jboss Fuse8/7/201517/6/2026
Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.
ModificadaBaja (3.6)1.0%💥 ExploitDebian LinuxFuse Project Fuse2/7/201517/6/2026
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
ModificadaMedia (4.3)0.83%—Async-http-client Project Async-http-clientRedhat Jboss Fuse24/6/201517/6/2026
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
ModificadaMedia (4.3)0.99%—Redhat Jboss FuseAsync-http-client Project Async-http-client24/6/201517/6/2026
Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitElasticsearchRedhat Fuse17/2/201517/6/2026
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
ModificadaMedia (6.8)0.92%—Redhat Jboss FuseIgniterealtime Smack API25/10/201417/6/2026
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an…
ModificadaMedia (6.5)1.7%—Redhat Jboss Fuse Service WorksRedhat Jboss Overlord RUN Time Governance22/4/201417/6/2026
JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression Language (MVEL) expression. NOTE: some of these details are obtained from third party information.
ModificadaBaja (2.1)0.37%—Redhat Jboss A-mqRedhat Jboss Fuse17/4/201417/6/2026
JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs…
ModificadaMedia (4.3)2.2%—Redhat Jboss A-mqRedhat Jboss Fuse30/9/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ 6.0.0 before patch 3 allow remote attackers to inject arbitrary web script or HTML via the (1) user field in the create user page or (2) profile version to the create profile page.
ModificadaMedia (6.4)6.3%💥 PoCApache CXFRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise SOA Platform+219/8/201316/6/2026
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended…
ModificadaBaja (2.6)2.1%—Fusedpress Buddypress-extended-frienship-request29/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in the BuddyPress Extended Friendship Request plugin before 1.0.2 for WordPress, when the "Friend Connections" component is enabled, allows remote attackers to inject arbitrary web script or HTML via the friendship_request_message parameter to wp-admin/admin-ajax.php. NOTE:…
ModificadaMedia (4.3)1.6%💥 ExploitFusetalkFusetalk. Fusetalk4/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk Forums 3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the windowed parameter.
ModificadaAlta (7.5)1.0%💥 ExploitFusebox2/11/201116/6/2026
SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL commands via the CatDisplay parameter.
ModificadaBaja (3.3)0.33%—Fuse2/9/201116/6/2026
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.
ModificadaBaja (3.3)0.32%—Fuse2/9/201116/6/2026
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.
ModificadaBaja (3.3)0.32%—Fuse2/9/201116/6/2026
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
ModificadaMedia (5.8)9.8%💥 ExploitLibfuse Project Libfuse22/1/201116/6/2026
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
ModificadaBaja (3.3)0.39%—Fuse2/3/201016/6/2026
fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.
RechazadaSin puntuar——SambaAINcpfsAIFuseAI2/3/20107/11/2023
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-0787, CVE-2010-0788, CVE-2010-0789. Reason: this candidate was intended for one issue in Samba, but it was used for multiple distinct issues, including one in FUSE and one in ncpfs. Notes: All CVE users should consult CVE-2010-0787 (Samba),…
ModificadaMedia (4.6)0.36%—Afuse17/7/200816/6/2026
The expand_template function in afuse.c in afuse 0.2 allows local users to gain privileges via shell metacharacters in a pathname.
Orbitaley — Vulnerabilidades