Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

174 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.6)0.82%—Pivotal Software Spring Data JPA5/10/201617/6/2026
SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call.
ModificadaAlta (8.8)1.7%—Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry OPS Manager+130/9/201617/6/2026
The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5; UAA BOSH before 11.7 and 12.x before 12.6; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.2; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1…
ModificadaCrítica (9.6)0.73%—Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry OPS Manager+130/9/201617/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.2; and Ops Manager 1.7.x before…
ModificadaMedia (5.3)1.4%—Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry OPS Manager+130/9/201617/6/2026
The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.1; and Ops Manager 1.7.x before 1.7.13 and 1.8.x…
ModificadaAlta (7.5)1.7%—Cloudfoundry Php-buildpackPivotal Cloud Foundry Elastic Runtime18/9/201617/6/2026
Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file in the htdocs directory, which might allow remote attackers to obtain sensitive…
ModificadaCrítica (9.8)1.0%—Pivotal Operations Manager18/9/201617/6/2026
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting within an installation-time period during which these VMs exist.
ModificadaAlta (7.5)1.1%—Pivotal Software Rabbitmq18/9/201617/6/2026
The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.
ModificadaAlta (7.4)1.4%—Pivotal Cloud Foundry Elastic Runtime18/9/201617/6/2026
Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7.8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (6.1)1.0%—Pivotal Software Cloud Foundry Elastic Runtime18/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.1)1.1%—Pivotal Software Cloud Foundry Elastic Runtime18/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts with the AngularJS framework.
ModificadaCrítica (9.8)1.5%—Pivotal Software Operations Manager18/9/201617/6/2026
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecified impact and remote attack vectors.
ModificadaAlta (7.3)1.0%—Pivotal Software Cloud Foundry Elastic Runtime18/9/201617/6/2026
Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, which might allow remote attackers to bypass intended network-connectivity restrictions by leveraging access to the 169.254.169.254 address.
ModificadaCrítica (9.8)0.90%—Pivotal Software Operations Manager18/9/201617/6/2026
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.
ModificadaMedia (5.5)2.6%—Pivotal Software Spring FrameworkVmware Spring FrameworkFedoraproject Fedora12/7/201617/6/2026
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
ModificadaMedia (5)1.9%—Pivotal Software Spring FrameworkVmware Spring Framework10/3/201517/6/2026
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
ModificadaMedia (5)6.3%—Pivotal Software Spring Framework19/2/201517/6/2026
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
ModificadaMedia (5)1.4%—Pivotal Software Rabbitmq20/1/201517/6/2026
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
ModificadaBaja (3.5)1.2%—Pivotal Software Rabbitmq Management18/1/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) message details when a message is unqueued, such as headers or arguments; (2) policy names, which are not properly…
ModificadaMedia (5)10%💥 PoCPivotal Software Spring FrameworkVmware Spring Framework20/11/201417/6/2026
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
ModificadaMedia (5)3.1%—Gopivotal Grails-resourcesGopivotal Grails15/4/201417/6/2026
Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability…
ModificadaMedia (5)1.4%—Gopivotal Grails-resourcesGopivotal Grails15/4/201417/6/2026
The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 does not properly restrict access to files in the META-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this issue was SPLIT from CVE-2014-0053 due to…
ModificadaMedia (5)2.0%—Gopivotal Grails-resourcesGopivotal Grails15/4/201417/6/2026
The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files in the WEB-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this identifier has been SPLIT due to different…
ModificadaMedia (4.3)6.9%—Pivotal Software Spring Framework20/3/201417/6/2026
Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.
ModificadaMedia (6.8)91%—Pivotal Software Spring FrameworkVmware Spring Framework26/1/201417/6/2026
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue,…
Orbitaley — Vulnerabilidades