Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 1.2% | — | Oracle Enterprise Manager Base Platform | 15/1/2020 | 17/6/2026 | Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.3) | 1.1% | — | Oracle Enterprise Manager Base Platform | 15/1/2020 | 17/6/2026 | Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (6) | 1.4% | — | Oracle Enterprise Manager Base Platform | 15/1/2020 | 17/6/2026 | Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Repository). Supported versions that are affected are 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base… | |
| Modificada | Alta (8.8) | 11% | — | OpencvOracle Application Testing SuiteOracle BIG Data Spatial AND GraphOracle Enterprise Manager Base Platform | 3/1/2020 | 17/6/2026 | An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to… | |
| Modificada | Alta (8.8) | 21% | — | OpencvOracle Application Testing SuiteOracle BIG Data Spatial AND GraphOracle Enterprise Manager Base Platform | 3/1/2020 | 17/6/2026 | An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this… | |
| Modificada | Crítica (9.8) | 8.6% | — | Fasterxml Jackson-databindOracle Banking PlatformOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Slice Selection Function+26 | 3/1/2020 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Crítica (9.8) | 14% | — | Apache CXFOracle Commerce Guided SearchOracle Enterprise Manager Base PlatformOracle Flexcube Private Banking+1 | 6/11/2019 | 17/6/2026 | Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If… | |
| Modificada | Media (5.5) | 1.00% | — | Apache POIOracle Application Testing SuiteOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+23 | 23/10/2019 | 17/6/2026 | In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing. | |
| Modificada | Media (6.4) | 0.92% | — | Oracle Business IntelligenceOracle Enterprise Manager Base PlatformOracle Mysql Server | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Crítica (9.8) | 11% | 💥 PoC | Connect2id Nimbus Jose+jwtApache HadoopOracle Communications Cloud Native Core Security Edge Protection ProxyOracle Communications Pricing Design Center+11 | 15/10/2019 | 17/6/2026 | Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass. | |
| Modificada | Crítica (9.8) | 16% | 💥 PoC | Softwareag QuartzOracle Apache Batik MapviewerOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+27 | 26/7/2019 | 17/6/2026 | initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. | |
| Modificada | Alta (7.5) | 9.8% | — | Apache CamelOracle Enterprise Data QualityOracle Enterprise Manager Base PlatformOracle Flexcube Private Banking+1 | 28/5/2019 | 17/6/2026 | Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed. | |
| Modificada | Alta (7.5) | 92% | 💥 Exploit | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+33 | 1/5/2019 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version… | |
| Analizada | Alta (7.5) | 4.9% | 💥 PoC | Mchange C3p0Fedoraproject FedoraOracle Communications IP Service ActivatorOracle Communications Session Route Manager+7 | 22/4/2019 | 17/6/2026 | c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration. | |
| Modificada | Media (5.3) | 5.9% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+22 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path.… | |
| Modificada | Media (5.3) | 4.1% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+21 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in… | |
| Modificada | Alta (7.5) | 12% | 💥 PoC | Apache ActivemqNetapp E-series Santricity WEB ServicesOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base Platform+4 | 28/3/2019 | 17/6/2026 | In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive. | |
| Modificada | Media (5.9) | 17% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+78 | 27/2/2019 | 17/6/2026 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid… | |
| Modificada | Media (6.5) | 1.2% | — | Oracle Enterprise Manager Base Platform | 16/1/2019 | 17/6/2026 | Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite (subcomponent: EM Console). Supported versions that are affected are 13.2 and 13.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager… | |
| Modificada | Media (4.7) | 3.4% | 💥 Exploit | Canonical Ubuntu LinuxDebian LinuxNodejs Node.jsOpenssl+16 | 15/11/2018 | 17/6/2026 | Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. | |
| Modificada | Media (5.9) | 12% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js+15 | 30/10/2018 | 17/6/2026 | The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected… | |
| Modificada | Media (5.9) | 4.7% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js+18 | 29/10/2018 | 17/6/2026 | The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1). | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache StrutsNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+4 | 22/8/2018 | 17/6/2026 | Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to… | |
| Modificada | Media (6.5) | 4.5% | — | IBM SDKRedhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 20/8/2018 | 17/6/2026 | The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882. |