Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.7) | 4.3% | — | Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+17 | 15/7/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java… | |
| Analizada | Baja (3.7) | 3.4% | — | Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+16 | 15/7/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE,… | |
| Modificada | Baja (3.7) | 3.4% | — | Oracle JDKNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage ManagerNetapp E-series Santricity Unified Manager+5 | 15/7/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability… | |
| Modificada | Media (5.3) | 5.2% | — | Oracle JDKNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage ManagerNetapp E-series Santricity Unified Manager+5 | 15/7/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability… | |
| Analizada | Media (4.8) | 3.0% | — | Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+16 | 15/7/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (4.9) | 0.34% | — | Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+20 | 5/5/2020 | 17/6/2026 | The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal. | |
| Modificada | Media (4.9) | 0.34% | — | Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+20 | 5/5/2020 | 17/6/2026 | The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator. | |
| Modificada | Media (4.9) | 0.72% | — | Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+20 | 5/5/2020 | 17/6/2026 | 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell… | |
| Modificada | Alta (8.8) | 2.3% | — | Jenkins Amazon WEB Services Serverless Application Model | 16/4/2020 | 17/6/2026 | Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. | |
| Modificada | Media (5.3) | 4.9% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+17 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.5) | 2.8% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+15 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in… | |
| Modificada | Alta (8.3) | 4.1% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+16 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (8.3) | 6.2% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+16 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (4.8) | 2.9% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+16 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple… | |
| Modificada | Media (5.3) | 4.9% | — | Oracle JDKOracle JREOracle OpenjdkDebian Linux+17 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE, Java… | |
| Modificada | Baja (3.7) | 2.4% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+16 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in… | |
| Modificada | Baja (3.7) | 3.9% | — | Oracle JDKOracle JREOracle OpenjdkFedoraproject Fedora+17 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (4.8) | 2.2% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+16 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in… | |
| Modificada | Baja (3.7) | 4.2% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+17 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Baja (3.7) | 4.2% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+16 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Baja (3.7) | 3.9% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+16 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Media (5.9) | 1.8% | — | Apache CXFApache Wss4jRedhat Jboss Business Rules Management SystemRedhat Jboss Enterprise Application Platform+6 | 11/3/2020 | 16/6/2026 | The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack. | |
| Modificada | Alta (8.8) | 2.1% | — | Restful WEB Services Project Restful WEB Services | 11/2/2020 | 16/6/2026 | The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct… | |
| Modificada | Baja (3.7) | 4.2% | — | Oracle JDKOracle JREOracle OpenjdkDebian Linux+19 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241 and 8u231; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java… | |
| Modificada | Baja (3.7) | 4.0% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+19 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of… |