Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

255 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)8.4%—NettyDebian LinuxCanonical Ubuntu LinuxRedhat Jboss Enterprise Application Platform26/9/201917/6/2026
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
ModificadaCrítica (9.8)5.0%—Fasterxml Jackson-databindFedoraproject FedoraDebian LinuxNetapp Oncommand API Services+1315/9/201917/6/2026
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
ModificadaCrítica (9.8)11%💥 PoCFasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationNetapp Steelstore Cloud Integrated Storage+1515/9/201917/6/2026
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
ModificadaMedia (5.5)0.78%—Apache Santuario XML Security FOR JavaRedhat Jboss Enterprise Application PlatformOracle Weblogic Server23/8/201917/6/2026
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might…
ModificadaAlta (7.3)28%—Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+5620/8/201925/8/2026
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
ModificadaAlta (7.5)25%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1413/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each…
ModificadaAlta (7.5)28%—Apple SwiftnioApache Http ServerApache Traffic ServerCanonical Ubuntu Linux+1913/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The…
ModificadaMedia (6.5)56%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1513/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and…
ModificadaAlta (7.5)87%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1813/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a…
ModificadaAlta (7.5)83%—Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+2413/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can…
ModificadaAlta (7.5)82%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1613/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
ModificadaAlta (7.5)60%💥 PoCApple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1613/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to…
ModificadaCrítica (9.8)8.1%—Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+2029/7/201917/6/2026
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
ModificadaAlta (7.5)3.5%—Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+225/7/201917/6/2026
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
ModificadaCrítica (9)0.91%—Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on12/6/201917/6/2026
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.
ModificadaMedia (5.4)0.69%—Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on12/6/201917/6/2026
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.
ModificadaAlta (8.8)1.5%—Redhat WildflyRedhat Jboss Enterprise Application Platform3/5/201917/6/2026
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.
ModificadaMedia (4.7)0.19%—Redhat Jboss Enterprise Application PlatformRedhat Wildfly3/5/201917/6/2026
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
ModificadaMedia (5.4)0.95%—Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on27/3/201917/6/2026
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.
ModificadaAlta (7.5)8.9%—Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraOracle JD Edwards Enterpriseone Tools+721/3/201917/6/2026
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service…
ModificadaAlta (7.5)7.2%—Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraOracle JD Edwards Enterpriseone Tools+721/3/201917/6/2026
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access,…
ModificadaCrítica (10)10%—Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Communications Billing AND Revenue Management+82/1/201917/6/2026
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
ModificadaCrítica (9.8)7.5%—Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Communications Billing AND Revenue Management+82/1/201917/6/2026
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
ModificadaMedia (5.3)2.1%—Redhat UndertowRedhat Jboss Enterprise Application Platform18/9/201817/6/2026
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
ModificadaAlta (7.8)0.30%—Redhat Jboss Enterprise Application Platform11/9/201817/6/2026
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.