Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.69% | 💥 PoC | Pyinstaller | 14/1/2020 | 17/6/2026 | In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software using PyInstaller in "onefile" mode is launched by a privileged user (at least more than the current one) which have his "TempPath" resolving to a world writable directory.… | |
| Modificada | Crítica (9.8) | 8.6% | — | Fasterxml Jackson-databindOracle Banking PlatformOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Slice Selection Function+26 | 3/1/2020 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. | |
| Modificada | Media (4.7) | 1.1% | — | Oracle Installed Base | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are affected are 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful… | |
| Modificada | Crítica (9.8) | 5.4% | — | Fasterxml Jackson-databindDebian LinuxRedhat Jboss Enterprise Application PlatformOracle Banking Platform+18 | 12/10/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide… | |
| Modificada | Alta (7.8) | 8.2% | 💥 Exploit | Linuxmint Mintinstall | 2/10/2019 | 17/6/2026 | mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports. | |
| Modificada | Crítica (9.8) | 4.9% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraRedhat Jboss Enterprise Application Platform+22 | 1/10/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint… | |
| Modificada | Crítica (9.8) | 5.7% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraRedhat Jboss Enterprise Application Platform+24 | 1/10/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service… | |
| Modificada | Alta (7.8) | 0.94% | — | Bitrock Installbuilder | 29/8/2019 | 17/6/2026 | Windows binaries generated with InstallBuilder versions earlier than 19.7.0 are vulnerable to tampering even if they contain a valid Authenticode signature. | |
| Modificada | Media (6.5) | 0.61% | — | Wordpress Uninstall Project Wordpress Uninstall | 20/8/2019 | 17/6/2026 | The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=uninstall URI. | |
| Modificada | Alta (7.5) | 11% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraApache Drill+14 | 30/7/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath. | |
| Modificada | Crítica (9.8) | 8.1% | — | Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+20 | 29/7/2019 | 17/6/2026 | SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution. | |
| Analizada | Alta (7.8) | 90% | ⚠ Explotación activa💥 Exploit | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 18/1/2019 | 1/10/2026 | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 13% | — | Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Business Process Management Suite+21 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization. | |
| Modificada | Alta (7.8) | 1.5% | — | Nullsoft Scriptable Install SystemDebian Linux | 1/10/2018 | 17/6/2026 | Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime. | |
| Modificada | Media (5.5) | 0.39% | — | Nullsoft Scriptable Install SystemDebian Linux | 1/10/2018 | 17/6/2026 | Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program. | |
| Modificada | Alta (8.1) | 1.7% | — | Co-cli-installer Project Co-cli-installer | 4/6/2018 | 17/6/2026 | co-cli-installer downloads the co-cli module as part of the install process, but does so over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or… | |
| Modificada | Alta (8.1) | 1.7% | — | Jvminstall Project Jvminstall | 1/6/2018 | 17/6/2026 | jvminstall is a module for downloading and unpacking jvm to local system. jvminstall downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on… | |
| Modificada | Media (5.9) | 0.55% | — | Install-g-test Project Install-g-test | 1/6/2018 | 17/6/2026 | install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks. | |
| Modificada | Alta (8.1) | 1.7% | — | Atom-node-module-installer Project Atom-node-module-installer | 1/6/2018 | 17/6/2026 | atom-node-module-installer installs node modules for atom-shell applications. atom-node-module-installer binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the… | |
| Modificada | Alta (8.1) | 1.7% | — | Pngcrush-installer Project Pngcrush-installer | 29/5/2018 | 17/6/2026 | pngcrush-installer is an installer for Pngcrush. pngcrush-installer versions below 1.8.10 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is… | |
| Modificada | Alta (8.1) | 1.7% | — | Install-nw Project Install-nw | 29/5/2018 | 17/6/2026 | install-nw is a module which quickly and robustly installs and caches NW.js. install-nw versions below 1.1.5 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary… | |
| Modificada | Alta (8.8) | 2.5% | — | Pivotal Software Spring SecurityVmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+38 | 11/5/2018 | 25/8/2026 | Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. | |
| Modificada | Baja (3.3) | 0.21% | — | Docutracinc Dtisqlinstaller | 19/3/2018 | 17/6/2026 | Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contains a hard-coded cryptographic salt, "S@l+&pepper". | |
| Modificada | Crítica (10) | 1.6% | — | Docutracinc Dtisqlinstaller | 19/3/2018 | 17/6/2026 | Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain three credentials with known passwords: QDMaster, OTMaster, and sa. | |
| Modificada | Alta (7.8) | 0.38% | — | Keycloak-httpd-client-install Project Keycloak-httpd-client-install | 20/1/2018 | 17/6/2026 | keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users. |