Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
942 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.37% | — | Cyclonedx-core-javaAI | 10/11/2025 | 17/6/2026 | The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Starting in version 2.1.0 and prior to version 11.0.1, the XML `Validator` used by cyclonedx-core-java was not configured securely, making the library vulnerable to XML… | |
| Analizada | Crítica (9.8) | 2.3% | — | Jorenbroekema Javascript Expression EvaluatorSilentmatt Javascript Expression Evaluator | 5/11/2025 | 17/6/2026 | The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted context object or use MEMBER of the context object into the evaluate() function and… | |
| Aplazada | Media (4.4) | 0.19% | — | CSS Javascript ToolboxAI | 1/11/2025 | 17/6/2026 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 12.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Aplazada | Media (5.9) | 0.16% | — | Legion OF THE Bouncy Castle INC Bouncy Castle FOR Java FipsAIBouncycastle Bouncy Castle FOR Java LTSAI | 24/10/2025 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files… | |
| Analizada | Media (5.9) | 0.23% | — | Oracle Java Virtual Machine | 21/10/2025 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can… | |
| Aplazada | Media (6.4) | 0.26% | — | Async JavascriptAI | 18/10/2025 | 17/6/2026 | The Async JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.19.07.14. This is due to missing authorization checks on the aj_steps AJAX aciton along with a lack on sanitization on the settings saved via the function. This makes it possible for authenticated… | |
| Aplazada | Media (4) | 0.32% | — | Xmlunit FOR JavaAI | 17/10/2025 | 1/10/2026 | XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled. | |
| Aplazada | Media (6.4) | 0.41% | — | Matrix Javascript SDKAI | 14/10/2025 | 17/6/2026 | Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to remotely execute arbitrary code. ParseObject.fromJSON, ParseObject.pin, ParseObject.registerSubclass, ObjectStateMutations (internal), and encode/decode… | |
| Aplazada | Alta (8.7) | 0.49% | — | Minio Java SDKAI | 30/9/2025 | 17/6/2026 | MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were automatically substituted with their… | |
| Analizada | Media (6.5) | 0.35% | — | Parseplatform Parse Javascript SDK | 24/9/2025 | 17/6/2026 | parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the… | |
| Analizada | Crítica (10) | 2.1% | — | Hubspot Jinjava | 17/9/2025 | 17/6/2026 | jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.8.1, by using mapper.getTypeFactory().constructFromCanonical(), it is possible to instruct the underlying ObjectMapper to deserialize attacker-controlled input into arbitrary classes. This enables… | |
| Aplazada | Baja (2.7) | 0.24% | — | Matrix Javascript SDKAI | 16/9/2025 | 17/6/2026 | Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in MatrixClient::getJoinedRooms, allowing a remote attacker to attempt to replace a tombstoned room with an unrelated attacker-supplied room. The issue… | |
| Analizada | Baja (2.1) | 0.35% | — | Linlinjava Litemall | 12/9/2025 | 17/6/2026 | A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of the file /wx/aftersale/cancel. Executing manipulation of the argument ID can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and… | |
| Aplazada | Baja (3.4) | 0.14% | — | SAP Netweaver AS JavaAIAdobe Document ServiceAIOpensslAI | 9/9/2025 | 17/6/2026 | SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and modify system information.This vulnerability has a low impact on… | |
| Analizada | Media (5.3) | 0.30% | — | SAP Netweaver Application Server Java | 9/9/2025 | 17/6/2026 | SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This… | |
| Aplazada | Media (4.3) | 0.24% | — | SAP Netweaver AS JavaAI | 9/9/2025 | 17/6/2026 | Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifiers by conducting a brute force search. By leveraging knowledge of several identifiers generated close to the same time, the attacker could… | |
| Aplazada | Crítica (9.9) | 0.72% | — | SAP Netweaver AS JavaAI | 9/9/2025 | 17/6/2026 | SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availability of the system. | |
| Aplazada | Ninguna (0) | 0.17% | — | Bouncycastle Bouncy Castle FOR JavaAI | 22/8/2025 | 17/6/2026 | Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0. | |
| Aplazada | Media (5.9) | 0.16% | — | Legion OF THE Bouncy Castle INC Bouncy Castle FOR Java FipsAIBouncycastle Bouncy Castle FOR Java LTSAI | 22/8/2025 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files… | |
| Aplazada | Baja (1) | 0.15% | — | Bouncycastle Bouncy Castle FOR JavaAI | 16/8/2025 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader. This issue affects Bouncy Castle for Java - BC-FJA… | |
| Analizada | Baja (2.1) | 0.33% | — | Linlinjava Litemall | 15/8/2025 | 17/6/2026 | A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file /admin/config/express of the component Business Logic Handler. The manipulation of the argument litemall_express_freight_min leads to business logic errors. The attack can be… | |
| Analizada | Baja (2.9) | 0.53% | — | Linlinjava Litemall | 14/8/2025 | 17/6/2026 | A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/util/JwtHelper.java of the component JSON Web Token Handler. The manipulation of the argument SECRET with the input… | |
| Analizada | Baja (2.1) | 0.37% | — | Linlinjava Litemall | 14/8/2025 | 17/6/2026 | A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminStorageController.java of the component Endpoint. The manipulation of the argument File leads to unrestricted upload. The… | |
| Aplazada | Alta (7.5) | 0.61% | — | Wipeoutmedia CSS Javascript ToolboxAIPHPAI | 14/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wipeoutmedia CSS & JavaScript Toolbox css-javascript-toolbox allows PHP Local File Inclusion.This issue affects CSS & JavaScript Toolbox: from n/a through < 12.0.3. | |
| Aplazada | Media (6.3) | 0.46% | — | Legion OF THE Bouncy Castle INC BC Java BcpkixAILegion OF THE Bouncy Castle INC BC Java BcprovAILegion OF THE Bouncy Castle INC Bcpkix FipsAI | 13/8/2025 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API modules) allows Excessive Allocation.… |