Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
258 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 2.5% | — | Redhat Jboss Enterprise Application Platform | 3/10/2016 | 17/6/2026 | Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL. | |
| Modificada | Alta (7.2) | 6.9% | — | Apache ArtemisRedhat Jboss Enterprise Application Platform | 27/9/2016 | 17/6/2026 | The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute… | |
| Modificada | Alta (8.8) | 2.9% | — | Redhat Jboss Enterprise Application Platform | 26/9/2016 | 17/6/2026 | The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves. | |
| Modificada | Media (6.1) | 2.5% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Wildfly Application Server | 26/9/2016 | 17/6/2026 | CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.6% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerFedoraproject Fedora | 26/9/2016 | 17/6/2026 | mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element. | |
| Modificada | Alta (7.5) | 95% | 💥 PoC | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss WEB ServerRedhat Enterprise Linux+5 | 1/9/2016 | 17/6/2026 | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated… | |
| Modificada | Crítica (9.8) | 4.7% | — | Redhat JgroupsRedhat Jboss Enterprise Application Platform | 30/6/2016 | 17/6/2026 | It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message… | |
| Modificada | Alta (7.5) | 2.6% | — | Jboss Enterprise Application Platform | 6/5/2016 | 17/6/2026 | The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshake, aka a read-timeout vulnerability. | |
| Modificada | Baja (3.5) | 1.8% | — | Redhat Jboss Enterprise Application Platform | 16/12/2015 | 17/6/2026 | Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the server, which allows remote authenticated users with the Monitor, Deployer, or Auditor role to cause a denial of service via unspecified vectors. | |
| Modificada | Media (5) | 3.0% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Wildfly Application Server | 27/10/2015 | 17/6/2026 | The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header. | |
| Modificada | Media (6.8) | 1.1% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Wildfly Application Server | 27/10/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.CR9 allows remote attackers to hijack the authentication of administrators for requests that make arbitrary changes to an… | |
| Modificada | Media (4.3) | 1.7% | — | Redhat Jboss Wildfly Application ServerRedhat Jboss Enterprise Application Platform | 27/10/2015 | 17/6/2026 | The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element. | |
| Modificada | Baja (2.1) | 0.37% | — | Redhat Jboss Enterprise Application Platform | 21/4/2015 | 17/6/2026 | The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors. | |
| Modificada | Baja (3.6) | 0.80% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms Platform | 20/2/2015 | 17/6/2026 | PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application. | |
| Modificada | Media (4) | 1.2% | — | Redhat Jboss Operations NetworkRedhat Jboss Enterprise Application Platform | 13/2/2015 | 17/6/2026 | The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging… | |
| Modificada | Media (4) | 1.3% | — | Redhat Jboss Enterprise Application Platform | 13/2/2015 | 17/6/2026 | The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role. | |
| Modificada | Baja (3.5) | 1.7% | — | Redhat Jboss Enterprise Application Platform | 13/2/2015 | 17/6/2026 | The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authenticated users to bypass intended access restrictions by… | |
| Modificada | Baja (2.1) | 0.35% | — | Redhat Jboss Enterprise Application Platform | 17/11/2014 | 17/6/2026 | JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file. | |
| Modificada | Alta (7.5) | 4.6% | — | Redhat Jboss Enterprise Application PlatformRedhat Resteasy | 19/8/2014 | 17/6/2026 | RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified… | |
| Modificada | Media (4.9) | 1.7% | — | Redhat Jboss Enterprise Application Platform | 19/8/2014 | 17/6/2026 | The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors. | |
| Modificada | Media (5.5) | 1.1% | — | Redhat Jboss Enterprise Application Platform | 19/8/2014 | 17/6/2026 | The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging… | |
| Modificada | Alta (7.5) | 3.9% | — | Redhat Jboss Enterprise Application Platform | 22/7/2014 | 17/6/2026 | The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary code and possibly have other unspecified impact via unspecified… | |
| Modificada | Media (6.8) | 2.6% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise SOA Platform | 22/7/2014 | 17/6/2026 | jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Portal Platform 5.2.2, and Red Hat JBoss SOA Platform 5.3.1, does not properly implement the JSR 160 specification, which allows remote attackers to execute arbitrary code… | |
| Modificada | Media (6.8) | 86% | 💥 Exploit | Apache Http ServerDebian LinuxRedhat Jboss Enterprise Application PlatformOracle Enterprise Manager OPS Center+2 | 20/7/2014 | 17/6/2026 | Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the… | |
| Modificada | Media (4.3) | 37% | — | Apache Http ServerDebian LinuxRedhat Jboss Enterprise Application Platform | 20/7/2014 | 17/6/2026 | The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size. |