Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
174 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.6) | 0.82% | — | Pivotal Software Spring Data JPA | 5/10/2016 | 17/6/2026 | SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call. | |
| Modificada | Alta (8.8) | 1.7% | — | Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry OPS Manager+1 | 30/9/2016 | 17/6/2026 | The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5; UAA BOSH before 11.7 and 12.x before 12.6; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.2; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1… | |
| Modificada | Crítica (9.6) | 0.73% | — | Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry OPS Manager+1 | 30/9/2016 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.2; and Ops Manager 1.7.x before… | |
| Modificada | Media (5.3) | 1.4% | — | Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry OPS Manager+1 | 30/9/2016 | 17/6/2026 | The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.1; and Ops Manager 1.7.x before 1.7.13 and 1.8.x… | |
| Modificada | Alta (7.5) | 1.7% | — | Cloudfoundry Php-buildpackPivotal Cloud Foundry Elastic Runtime | 18/9/2016 | 17/6/2026 | Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file in the htdocs directory, which might allow remote attackers to obtain sensitive… | |
| Modificada | Crítica (9.8) | 1.0% | — | Pivotal Operations Manager | 18/9/2016 | 17/6/2026 | Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting within an installation-time period during which these VMs exist. | |
| Modificada | Alta (7.5) | 1.1% | — | Pivotal Software Rabbitmq | 18/9/2016 | 17/6/2026 | The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line. | |
| Modificada | Alta (7.4) | 1.4% | — | Pivotal Cloud Foundry Elastic Runtime | 18/9/2016 | 17/6/2026 | Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7.8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (6.1) | 1.0% | — | Pivotal Software Cloud Foundry Elastic Runtime | 18/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 1.1% | — | Pivotal Software Cloud Foundry Elastic Runtime | 18/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts with the AngularJS framework. | |
| Modificada | Crítica (9.8) | 1.5% | — | Pivotal Software Operations Manager | 18/9/2016 | 17/6/2026 | Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecified impact and remote attack vectors. | |
| Modificada | Alta (7.3) | 1.0% | — | Pivotal Software Cloud Foundry Elastic Runtime | 18/9/2016 | 17/6/2026 | Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, which might allow remote attackers to bypass intended network-connectivity restrictions by leveraging access to the 169.254.169.254 address. | |
| Modificada | Crítica (9.8) | 0.90% | — | Pivotal Software Operations Manager | 18/9/2016 | 17/6/2026 | Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation. | |
| Modificada | Media (5.5) | 2.6% | — | Pivotal Software Spring FrameworkVmware Spring FrameworkFedoraproject Fedora | 12/7/2016 | 17/6/2026 | Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file. | |
| Modificada | Media (5) | 1.9% | — | Pivotal Software Spring FrameworkVmware Spring Framework | 10/3/2015 | 17/6/2026 | The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors. | |
| Modificada | Media (5) | 6.3% | — | Pivotal Software Spring Framework | 19/2/2015 | 17/6/2026 | Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL. | |
| Modificada | Media (5) | 1.4% | — | Pivotal Software Rabbitmq | 20/1/2015 | 17/6/2026 | RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header. | |
| Modificada | Baja (3.5) | 1.2% | — | Pivotal Software Rabbitmq Management | 18/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) message details when a message is unqueued, such as headers or arguments; (2) policy names, which are not properly… | |
| Modificada | Media (5) | 10% | 💥 PoC | Pivotal Software Spring FrameworkVmware Spring Framework | 20/11/2014 | 17/6/2026 | Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling. | |
| Modificada | Media (5) | 3.1% | — | Gopivotal Grails-resourcesGopivotal Grails | 15/4/2014 | 17/6/2026 | Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability… | |
| Modificada | Media (5) | 1.4% | — | Gopivotal Grails-resourcesGopivotal Grails | 15/4/2014 | 17/6/2026 | The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 does not properly restrict access to files in the META-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this issue was SPLIT from CVE-2014-0053 due to… | |
| Modificada | Media (5) | 2.0% | — | Gopivotal Grails-resourcesGopivotal Grails | 15/4/2014 | 17/6/2026 | The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files in the WEB-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this identifier has been SPLIT due to different… | |
| Modificada | Media (4.3) | 6.9% | — | Pivotal Software Spring Framework | 20/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action. | |
| Modificada | Media (6.8) | 91% | — | Pivotal Software Spring FrameworkVmware Spring Framework | 26/1/2014 | 17/6/2026 | The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue,… |