Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

182 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaAlta (7.5)1.6%—Doorkeeper Project Doorkeeper13/7/201817/6/2026
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
ModificadaAlta (7.5)3.2%—Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Network Integrity+2425/6/201817/6/2026
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not…
ModificadaMedia (5.9)2.7%—Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Communications Diameter Signaling Router+2925/6/201825/8/2026
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a…
ModificadaAlta (7.5)8.5%—Apache ZookeeperDebian LinuxOracle Goldengate Stream Analytics21/5/201817/6/2026
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
ModificadaAlta (8.8)2.5%—Pivotal Software Spring SecurityVmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+3811/5/201825/8/2026
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
ModificadaMedia (6.5)3.0%—Vmware Spring FrameworkRedhat OpenshiftOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+2611/5/201817/6/2026
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that…
ModificadaCrítica (9.8)57%—Vmware Spring FrameworkOracle Application Testing SuiteOracle BIG Data DiscoveryOracle Communications Converged Application Server+1511/4/201817/6/2026
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can…
ModificadaAlta (7.5)3.1%—Vmware Spring FrameworkOracle Application Testing SuiteOracle BIG Data DiscoveryOracle Communications Converged Application Server+216/4/201817/6/2026
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to…
ModificadaMedia (5.9)34%💥 ExploitVmware Spring FrameworkOracle Application Testing SuiteOracle BIG Data DiscoveryOracle Communications Converged Application Server+246/4/201817/6/2026
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the…
ModificadaCrítica (9.8)77%💥 PoCVmware Spring FrameworkOracle Application Testing SuiteOracle BIG Data DiscoveryOracle Communications Converged Application Server+246/4/201817/6/2026
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can…
ModificadaMedia (6.1)1.4%—Doorkeeper Project Doorkeeper13/3/201817/6/2026
Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vulnerability in web view's OAuth app form, user authorization prompt web view that can result in Stored XSS on the OAuth Client's name will cause users interacting with it will execute payload. This attack appear to be exploitable via The…
ModificadaMedia (6.1)30%💥 PoCJqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+4318/1/201817/6/2026
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
ModificadaAlta (7.5)73%💥 ExploitApache ZookeeperDebian Linux10/10/201717/6/2026
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.
ModificadaAlta (8.8)5.6%—GNU Libtasn1Debian LinuxApache Bookkeeper22/5/201717/6/2026
Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding utility.
ModificadaCrítica (9.1)4.7%—Doorkeeper Project Doorkeeper23/1/201717/6/2026
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
ModificadaAlta (8.1)7.9%—Apache Zookeeper21/9/201617/6/2026
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.
ModificadaMedia (6.8)0.65%—Doorkeeper Project Doorkeeper31/12/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in doorkeeper before 1.4.1 allows remote attackers to hijack the authentication of unspecified victims for requests that read a user OAuth authorization code via unknown vectors.
ModificadaMedia (5.4)0.27%—Runkeeper - GPS Track RUN Walk22/9/201417/6/2026
The RunKeeper - GPS Track Run Walk (aka com.fitnesskeeper.runkeeper.pro) application 4.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5)3.9%—Opensuse LeapOpensuseGnugk GNU Gatekeeper31/8/201216/6/2026
GNU Gatekeeper before 3.1 does not limit the number of connections to the status port, which allows remote attackers to cause a denial of service (connection and thread consumption) via a large number of connections.
ModificadaBaja (2.1)0.32%—Novell Suse Audit LOG Keeper8/8/201216/6/2026
The SUSE Audit Log Keeper daemon before 0.2.1-0.4.6.1 for SUSE Manager and Spacewalk uses world-readable permissions for /etc/auditlog-keeper.conf, which allows local users to obtain passwords by reading this file.
ModificadaMedia (5)2.3%—F-secure Internet Gatekeeper18/2/201116/6/2026
F-Secure Internet Gatekeeper for Linux 3.x before 3.03 does not require authentication for reading access logs, which allows remote attackers to obtain potentially sensitive information via a TCP session on the admin UI port.
ModificadaMedia (6.8)9.5%💥 ExploitSupachai Teasakul COM Sweetykeeper19/4/201016/6/2026
Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
ModificadaMedia (5)2.2%—F-secure Anti-virusF-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus FOR Citrix Servers+1015/4/201016/6/2026
F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, and for Linux 4.02 and earlier; Anti-Virus 2010 and earlier; Home Server Security 2009; Protection Service for Consumers 9 and earlier,…
ModificadaMedia (6.8)2.2%—F-secure Anti-virusF-secure Client SecurityF-secure Home Server SecurityF-secure Internet Gatekeeper+222/5/200916/6/2026
Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others;…
Orbitaley — Vulnerabilidades