Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

223 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.00%—Apache POIOracle Application Testing SuiteOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+2323/10/201917/6/2026
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
ModificadaCrítica (9.8)14%—Oracle Application Testing SuiteOracle Banking Enterprise CollectionsOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+1816/10/201917/6/2026
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and…
ModificadaAlta (7.5)8.9%—Bouncycastle Bc-javaApache TomeeNetapp Active IQ Unified ManagerNetapp Oncommand API Services+178/10/201917/6/2026
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
ModificadaCrítica (9.8)2.7%—Signal Private Messenger5/10/201917/6/2026
The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easier for remote attackers to cause a denial of service or possibly have unspecified other impact via malformed packets.…
ModificadaAlta (7.5)1.8%—Signal Private Messenger5/10/201917/6/2026
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is noticeable to the callee; however, the audio channel may be open before the callee can block eavesdropping.
ModificadaAlta (7.5)6.8%—TcpdumpF5 Traffix Signaling Delivery ControllerApple MAC OS XDebian Linux+33/10/201917/6/2026
The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option().
ModificadaAlta (7.5)3.9%—TcpdumpF5 Traffix Signaling Delivery ControllerApple MAC OS XDebian Linux+33/10/201917/6/2026
The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.
ModificadaAlta (7.5)5.3%💥 PoCTcpdumpApple MAC OS XDebian LinuxFedoraproject Fedora+193/10/201917/6/2026
The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().
ModificadaAlta (7)4.7%💥 PoCF5 Traffix Signaling Delivery ControllerTcpdumpApple MAC OS XDebian Linux+33/10/201917/6/2026
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
ModificadaAlta (7.5)5.3%💥 PoCTcpdumpF5 Traffix Signaling Delivery ControllerApple MAC OS XDebian Linux+33/10/201917/6/2026
The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().
ModificadaAlta (7.5)4.0%—TcpdumpApple MAC OS XDebian LinuxFedoraproject Fedora+193/10/201917/6/2026
The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().
ModificadaAlta (7.5)4.1%—TcpdumpF5 Traffix Signaling Delivery ControllerApple MAC OS XDebian Linux+33/10/201917/6/2026
The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().
ModificadaAlta (7.5)4.7%—TcpdumpF5 Traffix Signaling Delivery ControllerApple MAC OS XDebian Linux+33/10/201917/6/2026
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.
ModificadaAlta (7.5)4.0%—TcpdumpF5 Traffix Signaling Delivery ControllerApple MAC OS XDebian Linux+33/10/201917/6/2026
The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().
ModificadaMedia (6.1)2.5%—Eclipse MojarraOracle Mojarra Javaserver FacesOracle Application Testing SuiteOracle Banking Enterprise Product Manufacturing+192/10/201917/6/2026
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
ModificadaAlta (7.5)2.7%—Linux KernelCanonical Ubuntu LinuxF5 Traffix Signaling Delivery Controller23/9/201917/6/2026
In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized.
ModificadaMedia (5.4)1.1%—Onesignal-free-web-push-notifications30/8/201917/6/2026
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
ModificadaMedia (6.1)0.91%—Smokesignal Project Smokesignal21/8/201917/6/2026
The smokesignal plugin before 1.2.7 for WordPress has XSS.
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaAlta (7.5)11%💥 PoCFasterxml Jackson-databindDebian LinuxFedoraproject FedoraApache Drill+1430/7/201917/6/2026
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
ModificadaCrítica (9.8)8.1%—Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+2029/7/201917/6/2026
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
ModificadaAlta (7.5)5.0%—OpenldapCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+526/7/201917/6/2026
An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL…
ModificadaCrítica (9.8)95%—XstreamOracle Banking PlatformOracle Business Activity MonitoringOracle Communications Billing AND Revenue Management Elastic Charging Engine+623/7/201917/6/2026
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of…
ModificadaAlta (8.1)12%💥 PoCLibssh2Debian LinuxFedoraproject FedoraNetapp Cloud Backup+316/7/201917/6/2026
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of…
ModificadaAlta (7.5)2.5%—GnupgSKS Keyserver Project SKS KeyserverFedoraproject FedoraOpensuse Leap+129/6/201917/6/2026
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a…
Orbitaley — Vulnerabilidades