Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
446 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 13% | — | NettyDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+3 | 29/1/2020 | 17/6/2026 | HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header. | |
| Modificada | Crítica (9.1) | 8.9% | — | NettyDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+2 | 29/1/2020 | 17/6/2026 | HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold." | |
| Modificada | Alta (7.5) | 3.6% | — | NettyFedoraproject FedoraDebian LinuxRedhat Jboss Enterprise Application Platform+2 | 27/1/2020 | 17/6/2026 | Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869. | |
| Modificada | Media (4.3) | 0.74% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on | 23/1/2020 | 17/6/2026 | A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of confidential information. | |
| Modificada | Alta (7.5) | 0.91% | — | Redhat Jboss BrmsRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss Operations Network+2 | 23/1/2020 | 16/6/2026 | EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation. | |
| Modificada | Alta (7.5) | 2.1% | — | Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse+2 | 23/1/2020 | 17/6/2026 | A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL. | |
| Modificada | Media (4.3) | 0.72% | — | Redhat KeycloakRedhat Single Sign-onRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse | 8/1/2020 | 17/6/2026 | It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information. | |
| Modificada | Alta (8.8) | 1.2% | — | Redhat Single Sign-onRedhat Jboss Enterprise Application Platform | 7/1/2020 | 17/6/2026 | A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7… | |
| Modificada | Media (5.9) | 1.0% | — | Redhat Jboss Portal | 2/1/2020 | 17/6/2026 | It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, under high-concurrency scenarios or scenarios where SOAP messages take long to execute, it was possible for an unauthenticated remote attacker to gain privileged information… | |
| Modificada | Media (6.5) | 0.78% | — | Redhat Jboss Enterprise Application Platform | 2/1/2020 | 17/6/2026 | In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality,… | |
| Modificada | Crítica (9.8) | 2.0% | — | InfinispanRedhat Jboss Data Grid | 2/1/2020 | 17/6/2026 | A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling. | |
| Modificada | Media (6.1) | 4.0% | 💥 PoC | Smartbear Swagger-uiRedhat Jboss FuseRedhat Openshift | 20/12/2019 | 17/6/2026 | swagger-ui has XSS in key names | |
| Modificada | Alta (7.5) | 8.0% | — | Cyrusimap Cyrus-saslDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+15 | 19/12/2019 | 17/6/2026 | cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl. | |
| Modificada | Alta (7.8) | 0.29% | — | Redhat Jboss Application ServerRedhat Jboss Enterprise Application Platform | 18/12/2019 | 16/6/2026 | An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges. | |
| Modificada | Alta (8.1) | 1.5% | — | Redhat EdeployRedhat Jboss Enterprise WEB Server | 15/12/2019 | 17/6/2026 | eDeploy has tmp file race condition flaws | |
| Modificada | Crítica (9.8) | 2.4% | — | Redhat EdeployRedhat Jboss Enterprise WEB Server | 15/12/2019 | 17/6/2026 | eDeploy has RCE via cPickle deserialization of untrusted data | |
| Modificada | Media (6.1) | 0.65% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Portal | 11/12/2019 | 17/6/2026 | JBossWeb Bayeux has reflected XSS | |
| Modificada | Media (6.1) | 0.77% | 💥 PoC | Redhat Jboss Keycloak | 10/12/2019 | 17/6/2026 | JBoss KeyCloak: XSS in login-status-iframe.html | |
| Modificada | Baja (3.3) | 0.32% | — | Redhat Jboss Community Application ServerRedhat Jboss Enterprise WEB Server | 6/12/2019 | 16/6/2026 | An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Jboss Application Server | 26/11/2019 | 16/6/2026 | A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a… | |
| Modificada | Media (5.4) | 1.1% | — | Redhat Jboss Application Server | 26/11/2019 | 16/6/2026 | A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment… | |
| Modificada | Alta (8.8) | 3.1% | — | InfinispanRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+3 | 25/11/2019 | 17/6/2026 | A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application. | |
| Modificada | Crítica (9.8) | 2.8% | — | Redhat EdeployRedhat Jboss Enterprise WEB Server | 21/11/2019 | 17/6/2026 | eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data | |
| Modificada | Alta (7.5) | 17% | 💥 PoC | Fasterxml Jackson-mapper-aslRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseDebian Linux+1 | 18/11/2019 | 17/6/2026 | A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes. | |
| Modificada | Media (4.3) | 0.46% | — | Redhat KeycloakRedhat Jboss Enterprise WEB Server | 13/11/2019 | 17/6/2026 | JBoss KeyCloak is vulnerable to soft token deletion via CSRF |