Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 2.6% | — | Apache ANTOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Trade Finance+32 | 14/7/2021 | 25/8/2026 | When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR… | |
| Modificada | Media (5.5) | 2.5% | — | Apache ANTOracle Agile Product Lifecycle ManagementOracle Banking Trade FinanceOracle Banking Treasury Management+28 | 14/7/2021 | 25/8/2026 | When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected. | |
| Modificada | Alta (7.5) | 13% | — | Apache Commons CompressOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Enterprise Default Management+30 | 13/7/2021 | 17/6/2026 | When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package. | |
| Modificada | Alta (7.5) | 12% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+20 | 13/7/2021 | 17/6/2026 | When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package. | |
| Modificada | Alta (7.5) | 12% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+22 | 13/7/2021 | 17/6/2026 | When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package. | |
| Modificada | Crítica (9.8) | 1.1% | — | Connectwise Automate | 21/6/2021 | 17/6/2026 | An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132. | |
| Modificada | Alta (7.5) | 1.1% | — | Connectwise Automate | 17/6/2021 | 17/6/2026 | An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status responses. | |
| Modificada | Crítica (9.8) | 6.9% | — | PythonOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Slice Selection Function+2 | 6/5/2021 | 17/6/2026 | In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses. | |
| Modificada | Media (5.4) | 0.61% | — | Casap Automated Enrollment System Project Casap Automated Enrollment System | 15/4/2021 | 17/6/2026 | CASAP Automated Enrollment System version 1.0 contains a cross-site scripting (XSS) vulnerability through the Students > Edit > ROUTE parameter. | |
| Modificada | Media (4.3) | 1.1% | — | ElasticsearchOracle Communications Cloud Native Core Automated Test Suite | 8/3/2021 | 17/6/2026 | A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet… | |
| Modificada | Crítica (9.8) | 2.2% | — | Casap Automated Enrollment System Project Casap Automated Enrollment System | 15/2/2021 | 17/6/2026 | The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page. | |
| Modificada | Media (5.4) | 2.8% | 💥 Exploit | Casap Automated Enrollment System Project Casap Automated Enrollment System | 9/2/2021 | 9/7/2026 | CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website. | |
| Modificada | Media (4.8) | 1.2% | — | ElasticsearchOracle Communications Cloud Native Core Automated Test Suite | 14/1/2021 | 17/6/2026 | Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This… | |
| Modificada | Alta (8.8) | 1.2% | — | Connectwise Automate | 9/10/2020 | 17/6/2026 | The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions. | |
| Modificada | Crítica (9.8) | 1.3% | — | Connectwise Automate | 16/7/2020 | 17/6/2026 | ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12. | |
| Modificada | Alta (7.5) | 0.89% | — | Connectwise Automate | 7/7/2020 | 17/6/2026 | A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user supplied table name… | |
| Modificada | Alta (8.8) | 1.9% | — | Connectwise Automate API | 15/6/2020 | 17/6/2026 | By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions before 2019.12.337, 2020 before 2020.1.53, 2020.2… | |
| Modificada | Media (6.1) | 0.84% | — | Telos Automated Message Handling System | 3/1/2020 | 17/6/2026 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to… | |
| Modificada | Media (6.1) | 0.82% | — | Telos Automated Message Handling System | 3/1/2020 | 17/6/2026 | : Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5. | |
| Modificada | Media (6.1) | 0.84% | — | Telos Automated Message Handling System | 3/1/2020 | 17/6/2026 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prefs.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5. | |
| Modificada | Media (6.1) | 0.84% | — | Telos Automated Message Handling System | 3/1/2020 | 17/6/2026 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ModalWindowPopup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to… | |
| Modificada | Media (6.1) | 0.84% | — | Telos Automated Message Handling System | 3/1/2020 | 17/6/2026 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the LDAP cbURL parameter of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions… | |
| Modificada | Media (6.1) | 0.84% | — | Telos Automated Message Handling System | 3/1/2020 | 17/6/2026 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uploaditem.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to… | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (8.8) | 1.6% | — | JenkinsOracle Communications Cloud Native Core Automated Test SuiteRedhat Openshift Container Platform | 28/8/2019 | 17/6/2026 | Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user. |