Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 6.6% | — | Dom4j Project Dom4jDebian LinuxOracle Flexcube Investor ServicingOracle Primavera P6 Enterprise Project Portfolio Management+10 | 20/8/2018 | 17/6/2026 | dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML… | |
| Modificada | Crítica (9.8) | 19% | — | Eclipse JettyDebian LinuxOracle Rest Data ServicesOracle Retail Xstore Payment+15 | 26/6/2018 | 17/6/2026 | In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC… | |
| Modificada | Crítica (9.8) | 15% | — | Eclipse JettyDebian LinuxNetapp E-series Santricity ManagementNetapp E-series Santricity OS Controller+13 | 26/6/2018 | 17/6/2026 | In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk… | |
| Modificada | Alta (8.8) | 2.7% | — | Eclipse JettyNetapp E-series Santricity Management Plug-insNetapp E-series Santricity OS ControllerNetapp E-series Santricity WEB Services Proxy+8 | 22/6/2018 | 17/6/2026 | In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the… | |
| Modificada | Alta (7.5) | 7.3% | — | Canonical Ubuntu LinuxDebian LinuxPerlArchive\ \+5 | 7/6/2018 | 17/6/2026 | In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name. | |
| Modificada | Media (5.4) | 0.61% | — | Multidots Mass Pages/posts Creator | 31/5/2018 | 17/6/2026 | An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce or user capability check, so anyone can launch a DoS attack against a site and create hundreds of… | |
| Modificada | Alta (7.8) | 1.5% | 💥 Exploit | Usb-creator Project Usb-creator | 28/9/2017 | 17/6/2026 | usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call check_polkit for the KVMTest method. | |
| Modificada | Media (6.1) | 0.71% | — | Bobcares Gift-certificate-creator | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin gift-certificate-creator v1.0, The code in gc-list.php doesn't sanitize user input to prevent a stored XSS vulnerability. | |
| Modificada | Alta (7.5) | 8.3% | — | Apache TomcatDebian LinuxNetapp Oncommand InsightNetapp Oncommand Shift+11 | 11/8/2017 | 17/6/2026 | A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet. | |
| Modificada | Alta (7.5) | 8.1% | — | Apache TomcatOracle Tekelec Platform DistributionDebian LinuxNetapp Oncommand Insight+10 | 10/8/2017 | 17/6/2026 | The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web… | |
| Modificada | Media (5.3) | 7.2% | — | Apache TomcatDebian LinuxRedhat Jboss Enterprise WEB ServerRedhat Enterprise Linux Desktop+10 | 10/8/2017 | 17/6/2026 | When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be… | |
| Modificada | Crítica (9.1) | 10% | — | Apache TomcatNetapp Oncommand InsightNetapp Oncommand ShiftNetapp Snap Creator Framework+11 | 10/8/2017 | 17/6/2026 | In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications. | |
| Modificada | Media (5.9) | 8.0% | — | Apache TomcatCanonical Ubuntu LinuxDebian LinuxRedhat Jboss Enterprise WEB Server+11 | 10/8/2017 | 17/6/2026 | The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default… | |
| Modificada | Alta (7.8) | 0.50% | 💥 PoC | Ether Software Easy Avi/divx/xvid TO DVD BurnerEther Software Easy AVI Divx ConverterEther Software Easy CD DVD CopyEther Software Easy DVD Creator+14 | 30/4/2017 | 17/6/2026 | Buffer overflow in Ether Software Easy MOV Converter 1.4.24, Easy DVD Creator, Easy MPEG/AVI/DIVX/WMV/RM to DVD, Easy Avi/Divx/Xvid to DVD Burner, Easy MPEG to DVD Burner, Easy WMV/ASF/ASX to DVD Burner, Easy RM RMVB to DVD Burner, Easy CD DVD Copy, MP3/AVI/MPEG/WMV/RM to Audio CD Burner, MP3/WAV/OGG/WMA/AC3 to CD… | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa | Apache TomcatCanonical Ubuntu LinuxNetapp 7-mode Transition ToolNetapp Oncommand Insight+15 | 6/4/2017 | 25/8/2026 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427… | |
| Modificada | Media (6.3) | 0.53% | — | Netapp Snap Creator Framework | 7/2/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in NetApp Snap Creator Framework before 4.3.0P1 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. | |
| Modificada | Alta (7.5) | 1.7% | — | Netapp Snap Creator Framework | 21/12/2016 | 17/6/2026 | NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by an unauthorized user. | |
| Modificada | Alta (8.1) | 1.9% | — | Ietf Transport Layer SecurityNetapp Clustered Data Ontap Antivirus ConnectorNetapp Data Ontap EdgeNetapp Host Agent+9 | 21/9/2016 | 17/6/2026 | The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which… | |
| Modificada | Media (5.4) | 0.27% | — | Pokecreator Lite | 19/10/2014 | 17/6/2026 | The PokeCreator Lite (aka com.pokecreator.builderlite) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Aximediasoft Slide Show Creator | 10/9/2014 | 17/6/2026 | The Slide Show Creator (aka com.amem) application 4.4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Intsig Camscanner -phone PDF Creator | 9/9/2014 | 17/6/2026 | The CamScanner -Phone PDF Creator (aka com.intsig.camscanner) application 3.4.0.20140624 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.3% | — | Etoshop Classifieds Creator | 24/12/2013 | 17/6/2026 | Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Etoshop C2C Forward Auction Creator | 21/12/2013 | 17/6/2026 | Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) pa parameter to auction/asp/list.asp, or the (2) UserID or (3) Password to auction/casp/admin.asp. | |
| Modificada | Media (4.6) | 0.37% | — | Canonical Ubuntu LinuxEvan Dandrea Usb-creator | 3/10/2013 | 16/6/2026 | usb-creator 0.2.47 before 0.2.47.1, 0.2.40 before 0.2.40ubuntu2, and 0.2.38 before 0.2.38.2 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or… | |
| Modificada | Media (4.3) | 1.6% | — | Photogallerycreator Flash-album-gallery | 1/6/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in a flag-manage-gallery action. |