Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

446 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)13%—NettyDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+329/1/202017/6/2026
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
ModificadaCrítica (9.1)8.9%—NettyDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+229/1/202017/6/2026
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
ModificadaAlta (7.5)3.6%—NettyFedoraproject FedoraDebian LinuxRedhat Jboss Enterprise Application Platform+227/1/202017/6/2026
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
ModificadaMedia (4.3)0.74%—Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on23/1/202017/6/2026
A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of confidential information.
ModificadaAlta (7.5)0.91%—Redhat Jboss BrmsRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss Operations Network+223/1/202016/6/2026
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.
ModificadaAlta (7.5)2.1%—Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse+223/1/202017/6/2026
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
ModificadaMedia (4.3)0.72%—Redhat KeycloakRedhat Single Sign-onRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse8/1/202017/6/2026
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
ModificadaAlta (8.8)1.2%—Redhat Single Sign-onRedhat Jboss Enterprise Application Platform7/1/202017/6/2026
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7…
ModificadaMedia (5.9)1.0%—Redhat Jboss Portal2/1/202017/6/2026
It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, under high-concurrency scenarios or scenarios where SOAP messages take long to execute, it was possible for an unauthenticated remote attacker to gain privileged information…
ModificadaMedia (6.5)0.78%—Redhat Jboss Enterprise Application Platform2/1/202017/6/2026
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality,…
ModificadaCrítica (9.8)2.0%—InfinispanRedhat Jboss Data Grid2/1/202017/6/2026
A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.
ModificadaMedia (6.1)4.0%💥 PoCSmartbear Swagger-uiRedhat Jboss FuseRedhat Openshift20/12/201917/6/2026
swagger-ui has XSS in key names
ModificadaAlta (7.5)8.0%—Cyrusimap Cyrus-saslDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+1519/12/201917/6/2026
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
ModificadaAlta (7.8)0.29%—Redhat Jboss Application ServerRedhat Jboss Enterprise Application Platform18/12/201916/6/2026
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.
ModificadaAlta (8.1)1.5%—Redhat EdeployRedhat Jboss Enterprise WEB Server15/12/201917/6/2026
eDeploy has tmp file race condition flaws
ModificadaCrítica (9.8)2.4%—Redhat EdeployRedhat Jboss Enterprise WEB Server15/12/201917/6/2026
eDeploy has RCE via cPickle deserialization of untrusted data
ModificadaMedia (6.1)0.65%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Portal11/12/201917/6/2026
JBossWeb Bayeux has reflected XSS
ModificadaMedia (6.1)0.77%💥 PoCRedhat Jboss Keycloak10/12/201917/6/2026
JBoss KeyCloak: XSS in login-status-iframe.html
ModificadaBaja (3.3)0.32%—Redhat Jboss Community Application ServerRedhat Jboss Enterprise WEB Server6/12/201916/6/2026
An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
ModificadaMedia (6.5)1.3%—Redhat Jboss Application Server26/11/201916/6/2026
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a…
ModificadaMedia (5.4)1.1%—Redhat Jboss Application Server26/11/201916/6/2026
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment…
ModificadaAlta (8.8)3.1%—InfinispanRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+325/11/201917/6/2026
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
ModificadaCrítica (9.8)2.8%—Redhat EdeployRedhat Jboss Enterprise WEB Server21/11/201917/6/2026
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
ModificadaAlta (7.5)17%💥 PoCFasterxml Jackson-mapper-aslRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseDebian Linux+118/11/201917/6/2026
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
ModificadaMedia (4.3)0.46%—Redhat KeycloakRedhat Jboss Enterprise WEB Server13/11/201917/6/2026
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
Orbitaley — Vulnerabilidades