Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

251 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)8.3%—Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkOracle Blockchain Platform+1328/11/202017/6/2026
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely…
ModificadaAlta (8.8)0.65%—Softwaremill Akka-http-session27/11/202017/6/2026
This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by randomTokenCsrfProtection could be bypassed…
ModificadaAlta (7.5)1.4%💥 PoCPlaygroundsessions Playground Sessions23/11/202017/6/2026
Playground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with access to UserProfiles.sol to extract the email and password.
ModificadaAlta (7.5)11%—Apache BatikOracle API GatewayOracle Business IntelligenceOracle Communications Application Session Controller+1412/11/202017/6/2026
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
ModificadaBaja (2.6)0.59%—Cyberark Privileged Session Manager28/10/202017/6/2026
CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.
ModificadaAlta (7)4.4%—Eclipse JettyNetapp Snap Creator FrameworkNetapp SnapcenterNetapp Vasa Provider+1423/10/202017/6/2026
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared…
ModificadaMedia (6.5)11%💥 PoCVmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRMOracle Communications Design Studio+3419/9/202017/6/2026
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
ModificadaAlta (8.1)7.3%💥 PoCFasterxml Jackson-databindOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Autovue FOR Agile Product Lifecycle Management+2217/9/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
ModificadaCrítica (9.8)49%💥 PoCApache ActivemqOracle Communications Diameter Signaling RouterOracle Communications Element ManagerOracle Communications Session Report Manager+310/9/202017/6/2026
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack:…
ModificadaAlta (8.1)7.6%💥 PoCFasterxml Jackson-databindNetapp Active IQ Unified ManagerOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+2125/8/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
ModificadaAlta (7.5)89%—Apache Http ServerOracle Communications Element ManagerOracle Communications Session Report ManagerOracle Communications Session Route Manager+217/8/202017/6/2026
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
AnalizadaAlta (7.5)56%—Apache Http ServerNetapp Clustered Data OntapCanonical Ubuntu LinuxOpensuse Leap+97/8/202017/6/2026
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for…
ModificadaCrítica (9.8)90%💥 ExploitApache Http ServerNetapp Clustered Data OntapCanonical Ubuntu LinuxDebian Linux+97/8/202017/6/2026
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
ModificadaAlta (7.5)0.80%—Oracle Enterprise Session Border Controller15/7/202017/6/2026
Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications Applications (component: File Upload). Supported versions that are affected are 8.1.0, 8.2.0 and 8.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (4.7)0.32%—Oracle Communications Interactive Session Recorder15/7/202017/6/2026
Vulnerability in the Oracle Communications Interactive Session Recorder product of Oracle Communications Applications (component: FACE). Supported versions that are affected are 6.1-6.4. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications…
ModificadaAlta (7.4)5.2%—LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+1415/7/202017/6/2026
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
ModificadaAlta (8.1)4.5%💥 PoCFasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageDebian Linux+1016/6/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
AnalizadaAlta (8.1)8.6%—Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+814/6/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).
AnalizadaAlta (8.1)8.1%—Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageDebian Linux+914/6/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).
ModificadaAlta (8.1)4.5%—Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageDebian Linux+1114/6/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and…
ModificadaAlta (7)56%💥 ExploitApache TomcatDebian LinuxOpensuse LeapFedoraproject Fedora+2220/5/202025/8/2026
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is…
ModificadaMedia (6.7)0.38%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+219/5/202017/6/2026
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.
ModificadaMedia (6.7)0.38%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+219/5/202017/6/2026
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
ModificadaMedia (6.1)7.1%—Apache ActivemqOracle Communications Diameter Signaling RouterOracle Communications Element ManagerOracle Communications Session Report Manager+314/5/202017/6/2026
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
ModificadaCrítica (9.8)7.3%—Dom4j Project Dom4jOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Banking Platform+341/5/202025/8/2026
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Orbitaley — Vulnerabilidades