Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
223 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | — | Oracle Communications Diameter Signaling Router | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: User Interface). Supported versions that are affected are 8.0.0.0-8.4.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (5.4) | 0.73% | — | Oracle Communications Diameter Signaling Router | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: User Interface). Supported versions that are affected are 8.0.0.0-8.4.0.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.5) | 2.1% | — | PHPFedoraproject FedoraDebian LinuxOpensuse Leap+4 | 2/10/2020 | 17/6/2026 | In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data. | |
| Modificada | Alta (8.1) | 7.3% | 💥 PoC | Fasterxml Jackson-databindOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Autovue FOR Agile Product Lifecycle Management+22 | 17/9/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. | |
| Modificada | Media (5.9) | 4.5% | — | Apache ActivemqOracle Communications Diameter Signaling RouterOracle Flexcube Private BankingDebian Linux | 10/9/2020 | 17/6/2026 | Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original,… | |
| Modificada | Crítica (9.8) | 49% | 💥 PoC | Apache ActivemqOracle Communications Diameter Signaling RouterOracle Communications Element ManagerOracle Communications Session Report Manager+3 | 10/9/2020 | 17/6/2026 | A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack:… | |
| Modificada | Alta (8.1) | 7.6% | 💥 PoC | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+21 | 25/8/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP). | |
| Modificada | Media (6.5) | 5.6% | — | ISC BindFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+4 | 21/8/2020 | 17/6/2026 | In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an… | |
| Modificada | Alta (7.5) | 4.5% | — | Apache CamelOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base PlatformOracle Enterprise Repository | 8/7/2020 | 17/6/2026 | Server-Side Template Injection and arbitrary file disclosure on Camel templating components | |
| Modificada | Alta (8.1) | 4.5% | 💥 PoC | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageDebian Linux+10 | 16/6/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity). | |
| Analizada | Alta (8.1) | 8.6% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+8 | 14/6/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill). | |
| Analizada | Alta (8.1) | 8.1% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageDebian Linux+9 | 14/6/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2). | |
| Modificada | Alta (8.1) | 4.5% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageDebian Linux+11 | 14/6/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and… | |
| Modificada | Alta (7.5) | 6.0% | — | PerlNetapp Oncommand Workflow AutomationNetapp Snap Creator FrameworkFedoraproject Fedora+12 | 5/6/2020 | 17/6/2026 | regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls. | |
| Modificada | Alta (8.6) | 4.9% | — | PerlFedoraproject FedoraOpensuse LeapNetapp Oncommand Workflow Automation+13 | 5/6/2020 | 17/6/2026 | Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection. | |
| Modificada | Alta (8.2) | 11% | — | PerlFedoraproject FedoraOpensuse LeapOracle Communications Billing AND Revenue Management+11 | 5/6/2020 | 17/6/2026 | Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow. | |
| Modificada | Alta (7) | 56% | 💥 Exploit | Apache TomcatDebian LinuxOpensuse LeapFedoraproject Fedora+22 | 20/5/2020 | 25/8/2026 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is… | |
| Modificada | Media (5.3) | 1.1% | — | Signal Private MessengerSignal | 20/5/2020 | 17/6/2026 | Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined. | |
| Modificada | Media (6.1) | 7.1% | — | Apache ActivemqOracle Communications Diameter Signaling RouterOracle Communications Element ManagerOracle Communications Session Report Manager+3 | 14/5/2020 | 17/6/2026 | In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue. | |
| Modificada | Crítica (9.8) | 6.8% | — | Apache CamelOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base PlatformOracle Flexcube Private Banking | 14/5/2020 | 17/6/2026 | Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. | |
| Modificada | Crítica (9.8) | 5.7% | — | Apache CamelOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base PlatformOracle Flexcube Private Banking | 14/5/2020 | 17/6/2026 | Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. | |
| Modificada | Alta (7.5) | 14% | — | Apache CamelOracle Communications Diameter Intelligence HUBOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base Platform+1 | 14/5/2020 | 17/6/2026 | Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0. | |
| Modificada | Media (6.3) | 1.8% | — | Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+46 | 14/5/2020 | 17/6/2026 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an… | |
| Modificada | Crítica (9.8) | 7.3% | — | Dom4j Project Dom4jOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Banking Platform+34 | 1/5/2020 | 25/8/2026 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j. | |
| Modificada | Media (6.1) | 99% | 💥 Exploit | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. |