Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
446 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 87% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+18 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a… | |
| Modificada | Alta (7.5) | 83% | — | Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+24 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can… | |
| Modificada | Alta (7.5) | 82% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+16 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU. | |
| Modificada | Alta (7.5) | 60% | 💥 PoC | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+16 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to… | |
| Modificada | Baja (2.7) | 2.0% | — | Apache ActivemqRedhat Jboss A-mqRedhat Jboss Fuse | 1/8/2019 | 17/6/2026 | It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client. | |
| Modificada | Alta (7.5) | 11% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraApache Drill+14 | 30/7/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath. | |
| Modificada | Crítica (9.8) | 8.1% | — | Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+20 | 29/7/2019 | 17/6/2026 | SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution. | |
| Modificada | Alta (7.5) | 3.5% | — | Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+2 | 25/7/2019 | 17/6/2026 | undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api. | |
| Modificada | Crítica (9.8) | 3.0% | — | Redhat UndertowRedhat VirtualizationRedhat Virtualization HostRedhat Jboss Data Grid+2 | 12/6/2019 | 17/6/2026 | A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange) | |
| Modificada | Crítica (9) | 0.91% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on | 12/6/2019 | 17/6/2026 | It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks. | |
| Modificada | Media (5.4) | 0.69% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on | 12/6/2019 | 17/6/2026 | It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks. | |
| Modificada | Media (4.2) | 8.6% | — | Apache Http ServerCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+7 | 11/6/2019 | 17/6/2026 | A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled… | |
| Modificada | Alta (8.8) | 1.5% | — | Redhat WildflyRedhat Jboss Enterprise Application Platform | 3/5/2019 | 17/6/2026 | It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing. | |
| Modificada | Media (4.7) | 0.19% | — | Redhat Jboss Enterprise Application PlatformRedhat Wildfly | 3/5/2019 | 17/6/2026 | A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root. | |
| Modificada | Alta (7.4) | 6.2% | — | Apache QpidRedhat Jboss AMQ Clients 2Redhat OpenstackRedhat Satellite+6 | 23/4/2019 | 17/6/2026 | While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means… | |
| Analizada | Alta (7.8) | 65% | ⚠ Explotación activa💥 Exploit | Apache Http ServerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+23 | 8/4/2019 | 17/6/2026 | In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating… | |
| Modificada | Media (5.4) | 0.95% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on | 27/3/2019 | 17/6/2026 | A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users. | |
| Modificada | Alta (7.5) | 8.9% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraOracle JD Edwards Enterpriseone Tools+7 | 21/3/2019 | 17/6/2026 | An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service… | |
| Modificada | Alta (7.5) | 7.2% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraOracle JD Edwards Enterpriseone Tools+7 | 21/3/2019 | 17/6/2026 | An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access,… | |
| Modificada | Media (5.9) | 17% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+78 | 27/2/2019 | 17/6/2026 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid… | |
| Modificada | Media (5.3) | 20% | — | Apache Http ServerNetapp Santricity Cloud ConnectorNetapp Storage Automation StoreFedoraproject Fedora+8 | 30/1/2019 | 17/6/2026 | In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections. | |
| Modificada | Crítica (9.8) | 11% | — | Fasterxml Jackson-databindDebian LinuxOracle Business Process Management SuiteOracle Primavera P6 Enterprise Project Portfolio Management+8 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 11% | — | Fasterxml Jackson-databindDebian LinuxOracle Business Process Management SuiteOracle Primavera P6 Enterprise Project Portfolio Management+8 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 11% | — | Fasterxml Jackson-databindDebian LinuxOracle Business Process Management SuiteOracle Primavera P6 Enterprise Project Portfolio Management+8 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization. | |
| Modificada | Crítica (10) | 10% | — | Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Communications Billing AND Revenue Management+8 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization. |