Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 51% | 💥 PoC | OpensslDebian LinuxTenable LOG Correlation EngineTenable Nessus Network Monitor+17 | 16/2/2021 | 17/6/2026 | Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output… | |
| Modificada | Baja (3.7) | 3.0% | — | OpensslOracle Business IntelligenceOracle Enterprise Manager FOR Storage ManagementOracle Enterprise Manager OPS Center+4 | 16/2/2021 | 17/6/2026 | OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions greater than SSLv2 are supposed… | |
| Modificada | Media (6.5) | 16% | 💥 PoC | Nodejs Node.jsDebian LinuxFedoraproject FedoraOracle Graalvm+1 | 6/1/2021 | 17/6/2026 | Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling. | |
| Modificada | Alta (8.1) | 9.1% | — | Nodejs Node.jsDebian LinuxFedoraproject FedoraOracle Graalvm+1 | 6/1/2021 | 17/6/2026 | Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an… | |
| Modificada | Media (5.9) | 7.1% | 💥 PoC | OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+40 | 8/12/2020 | 17/6/2026 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both… | |
| Modificada | Media (5.5) | 0.65% | — | Musl-libc MuslDebian LinuxFedoraproject FedoraOracle Graalvm | 24/11/2020 | 17/6/2026 | In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow). | |
| Modificada | Alta (7.5) | 54% | 💥 PoC | Nodejs Node.jsFedoraproject FedoraOracle Blockchain PlatformOracle Graalvm+4 | 19/11/2020 | 17/6/2026 | A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1. | |
| Modificada | Crítica (9.8) | 69% | — | Y18n Project Y18nOracle GraalvmSiemens Sinec Infrastructure Network Services | 17/11/2020 | 17/6/2026 | The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution. | |
| Analizada | Media (5.3) | 3.2% | — | Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+15 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can… | |
| Modificada | Alta (7.2) | 1.5% | — | Oracle Graalvm | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: JVMCI). Supported versions that are affected are 19.3.2 and 20.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition.… | |
| Modificada | Alta (7.4) | 6.1% | — | Nodejs Node.jsOracle Banking Extensibility WorkbenchOracle Blockchain PlatformOracle Graalvm+1 | 8/6/2020 | 17/6/2026 | TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0. | |
| Modificada | Alta (7.5) | 5.3% | — | Nghttp2Debian LinuxOpensuse LeapFedoraproject Fedora+6 | 3/6/2020 | 17/6/2026 | In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at… | |
| Modificada | Baja (3.7) | 0.69% | — | Oracle Graalvm | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: Tools). Supported versions that are affected are 19.3.1 and 20.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition.… | |
| Modificada | Alta (7.7) | 1.3% | — | Oracle Graalvm | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler). Supported versions that are affected are 19.3.1 and 20.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise… | |
| Modificada | Media (6.3) | 0.92% | — | Oracle Graalvm | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler). Supported versions that are affected are 19.3.1 and 20.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle GraalVM… | |
| Modificada | Alta (7.5) | 1.7% | — | Apache NetbeansOracle Graalvm | 30/3/2020 | 17/6/2026 | The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability. | |
| Modificada | Crítica (9.1) | 2.3% | — | Apache NetbeansOracle Graalvm | 30/3/2020 | 17/6/2026 | The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and including 11.2 are affected by this… | |
| Modificada | Crítica (9.8) | 20% | — | Nodejs Node.jsOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle GraalvmDebian Linux+3 | 7/2/2020 | 17/6/2026 | Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons | |
| Modificada | Crítica (9.8) | 57% | 💥 PoC | Nodejs Node.jsDebian LinuxFedoraproject FedoraOpensuse Leap+9 | 7/2/2020 | 17/6/2026 | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed | |
| Modificada | Alta (7.5) | 20% | — | Nodejs Node.jsDebian LinuxOpensuse LeapRedhat Software Collections+6 | 7/2/2020 | 17/6/2026 | Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate | |
| Modificada | Alta (8.1) | 4.9% | — | Oracle Commerce Experience ManagerOracle Commerce Guided SearchOracle GraalvmOracle JDK+23 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Media (5.8) | 1.5% | — | Oracle Graalvm | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler). The supported version that is affected is 19.3.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise… | |
| Modificada | Media (4) | 0.40% | — | Oracle Graalvm | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: LLVM Interpreter). The supported version that is affected is 19.3.0.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GraalVM Enterprise Edition executes to… | |
| Modificada | Media (6.5) | 2.1% | — | Npmjs NPMOpensuse LeapOracle GraalvmFedoraproject Fedora+2 | 13/12/2019 | 17/6/2026 | Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also… | |
| Modificada | Alta (8.1) | 3.4% | — | Npmjs NPMOpensuse LeapOracle GraalvmFedoraproject Fedora+2 | 13/12/2019 | 17/6/2026 | Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to… |