Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
149 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Analizada | Crítica (9.8) | 93% | ⚠ Explotación activa💥 Exploit | Apache AuroraApache ShiroRedhat FuseRedhat Jboss Middleware Text-only Advisories | 7/6/2016 | 17/6/2026 | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter. | |
| Modificada | Alta (7.3) | 2.9% | — | Fuseiso Project FuseisoDebian LinuxFedoraproject Fedora | 30/3/2016 | 17/6/2026 | Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long pathname in an ISO file. | |
| Modificada | Alta (7.3) | 1.8% | — | Fedoraproject FedoraFuseiso Project Fuseiso | 30/3/2016 | 17/6/2026 | Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF block size in an ISO file, leading to a heap-based buffer overflow. | |
| Modificada | Alta (7.8) | 0.37% | — | Debian Fuse | 26/1/2016 | 17/6/2026 | An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world-writable permissions for the /dev/cuse character device, which allows local users to gain privileges via a character device in /dev, related to an ioctl. | |
| Modificada | Media (6) | 1.5% | — | Redhat Jboss Fuse | 8/7/2015 | 17/6/2026 | Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file. | |
| Modificada | Baja (3.6) | 1.0% | 💥 Exploit | Debian LinuxFuse Project Fuse | 2/7/2015 | 17/6/2026 | fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature. | |
| Modificada | Media (4.3) | 0.83% | — | Async-http-client Project Async-http-clientRedhat Jboss Fuse | 24/6/2015 | 17/6/2026 | main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate. | |
| Modificada | Media (4.3) | 0.99% | — | Redhat Jboss FuseAsync-http-client Project Async-http-client | 24/6/2015 | 17/6/2026 | Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | ElasticsearchRedhat Fuse | 17/2/2015 | 17/6/2026 | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script. | |
| Modificada | Media (6.8) | 0.92% | — | Redhat Jboss FuseIgniterealtime Smack API | 25/10/2014 | 17/6/2026 | The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an… | |
| Modificada | Media (6.5) | 1.7% | — | Redhat Jboss Fuse Service WorksRedhat Jboss Overlord RUN Time Governance | 22/4/2014 | 17/6/2026 | JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression Language (MVEL) expression. NOTE: some of these details are obtained from third party information. | |
| Modificada | Baja (2.1) | 0.37% | — | Redhat Jboss A-mqRedhat Jboss Fuse | 17/4/2014 | 17/6/2026 | JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs… | |
| Modificada | Media (4.3) | 2.2% | — | Redhat Jboss A-mqRedhat Jboss Fuse | 30/9/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ 6.0.0 before patch 3 allow remote attackers to inject arbitrary web script or HTML via the (1) user field in the create user page or (2) profile version to the create profile page. | |
| Modificada | Media (6.4) | 6.3% | 💥 PoC | Apache CXFRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise SOA Platform+2 | 19/8/2013 | 16/6/2026 | Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended… | |
| Modificada | Baja (2.6) | 2.1% | — | Fusedpress Buddypress-extended-frienship-request | 29/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the BuddyPress Extended Friendship Request plugin before 1.0.2 for WordPress, when the "Friend Connections" component is enabled, allows remote attackers to inject arbitrary web script or HTML via the friendship_request_message parameter to wp-admin/admin-ajax.php. NOTE:… | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | FusetalkFusetalk. Fusetalk | 4/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk Forums 3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the windowed parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Fusebox | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL commands via the CatDisplay parameter. | |
| Modificada | Baja (3.3) | 0.33% | — | Fuse | 2/9/2011 | 16/6/2026 | Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack. | |
| Modificada | Baja (3.3) | 0.32% | — | Fuse | 2/9/2011 | 16/6/2026 | fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors. | |
| Modificada | Baja (3.3) | 0.32% | — | Fuse | 2/9/2011 | 16/6/2026 | fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack. | |
| Modificada | Media (5.8) | 9.8% | 💥 Exploit | Libfuse Project Libfuse | 22/1/2011 | 16/6/2026 | FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789. | |
| Modificada | Baja (3.3) | 0.39% | — | Fuse | 2/3/2010 | 16/6/2026 | fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint. | |
| Rechazada | Sin puntuar | — | — | SambaAINcpfsAIFuseAI | 2/3/2010 | 7/11/2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-0787, CVE-2010-0788, CVE-2010-0789. Reason: this candidate was intended for one issue in Samba, but it was used for multiple distinct issues, including one in FUSE and one in ncpfs. Notes: All CVE users should consult CVE-2010-0787 (Samba),… | |
| Modificada | Media (4.6) | 0.36% | — | Afuse | 17/7/2008 | 16/6/2026 | The expand_template function in afuse.c in afuse 0.2 allows local users to gain privileges via shell metacharacters in a pathname. |