Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Verastream Host Integrator | 4/5/2020 | 17/6/2026 | Information disclosure vulnerability in Micro Focus Verastream Host Integrator (VHI) product, affecting versions earlier than 7.8 Update 1 (7.8.49 or 7.8.0.49). The vulnerability allows an unauthenticated attackers to view information they may not have been authorized to view. | |
| Modificada | Crítica (9.8) | 7.3% | — | Dom4j Project Dom4jOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Banking Platform+34 | 1/5/2020 | 25/8/2026 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j. | |
| Analizada | Media (6.1) | 85% | ⚠ Explotación activa💥 Exploit | JqueryDebian LinuxFedoraproject FedoraDrupal+48 | 29/4/2020 | 17/6/2026 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Baja (3.7) | 8.1% | 💥 PoC | Apache Log4jOracle Communications Application Session ControllerOracle Communications Billing AND Revenue ManagementOracle Communications Eagle FTP Table Base Retrieval+42 | 27/4/2020 | 17/6/2026 | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1 | |
| Modificada | Media (5.5) | 2.7% | — | Apache TikaOracle Flexcube Private BankingOracle Primavera UnifierOracle Webcenter Portal+1 | 27/4/2020 | 17/6/2026 | A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later.… | |
| Modificada | Media (5.4) | 0.91% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 15/4/2020 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Project Manager). Supported versions that are affected are 16.2.0.0 - 16.2.19.3, 17.12.0.0 - 17.12.17.0, 18.8.0.0 - 18.8.18.0, 19.12.1.0 - 19.12.3.0 and 20.1.0.0 - 20.2.0.0. Easily… | |
| Modificada | Media (6.5) | 0.71% | — | Oracle Primavera P6 Enterprise Project Portfolio Management | 15/4/2020 | 17/6/2026 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Project Manager). Supported versions that are affected are 16.2.0.0 - 16.2.19.3, 17.12.0.0 - 17.12.17.0, 18.8.0.0 - 18.8.18.0, 19.12.1.0 - 19.12.3.0 and 20.1.0.0 - 20.2.0.0. Easily… | |
| Modificada | Alta (8.1) | 5.8% | — | Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated Storage+14 | 7/4/2020 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly). | |
| Analizada | Alta (8.1) | 3.7% | — | Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated Storage+17 | 7/4/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop). | |
| Modificada | Media (6.5) | 1.1% | — | Jenkins Code Coverage API | 7/4/2020 | 17/6/2026 | Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Analizada | Alta (8.8) | 6.3% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+28 | 31/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). | |
| Analizada | Alta (8.8) | 3.6% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 31/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy). | |
| Modificada | Alta (8.8) | 3.6% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+21 | 31/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms). | |
| Modificada | Alta (8.8) | 3.6% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 26/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane. | |
| Modificada | Alta (8.8) | 3.6% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 26/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). | |
| Modificada | Alta (8.8) | 8.0% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 18/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus). | |
| Modificada | Alta (8.8) | 3.1% | — | Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+27 | 18/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms). | |
| Modificada | Alta (7.5) | 4.0% | — | Linuxfoundation DojoDebian LinuxOracle Communications Application Session ControllerOracle Communications Policy Management+6 | 10/3/2020 | 17/6/2026 | In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript… | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerDebian LinuxOracle Agile Product Lifecycle Management+21 | 2/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core). | |
| Modificada | Crítica (9.8) | 18% | 💥 Exploit | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerDebian LinuxOracle Autovue FOR Agile Product Lifecycle Management+12 | 2/3/2020 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap). | |
| Analizada | Crítica (9.8) | 4.6% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerDebian LinuxOracle Agile Product Lifecycle Management+27 | 2/3/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config). | |
| Modificada | Media (5.3) | 1.3% | — | Veraxsystems Network Management System | 30/1/2020 | 16/6/2026 | Verax NMS prior to 2.1.0 leaks connection details when any user executes a Repair Table action | |
| Modificada | Alta (7.5) | 1.3% | — | Veraxsystems Network Management System | 30/1/2020 | 16/6/2026 | Verax NMS prior to 2.1.0 uses an encryption key that is hardcoded in a JAR archive. | |
| Modificada | Media (5.9) | 2.0% | — | Veraxsystems Network Management System | 30/1/2020 | 16/6/2026 | Verax NMS prior to 2.10 allows authentication via the encrypted password without knowing the cleartext password. | |
| Modificada | Crítica (9.1) | 1.5% | — | Veraxsystems Network Management System | 30/1/2020 | 16/6/2026 | Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities |