Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)85%💥 ExploitXstreamDebian LinuxNetapp SnapmanagerApache Activemq+1116/11/20207/10/2026
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The…
ModificadaMedia (5.5)0.41%—Freedesktop Accountsservice11/11/202017/6/2026
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location.
ModificadaBaja (3.3)0.54%💥 PoCFreedesktop Accountsservice11/11/202017/6/2026
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion.
ModificadaMedia (6.1)0.84%—Quadient Mail Accounting28/10/202017/6/2026
NeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS.
ModificadaAlta (7.5)3.7%💥 PoCNetwrix Account Lockout Examiner20/10/202017/6/2026
Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a Domain Controller.
ModificadaMedia (4.9)1.0%—Frontaccounting30/9/202017/6/2026
An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.
ModificadaMedia (4.3)0.56%—SAP S/4 Hana Fiori UI FOR General Ledger Accounting12/8/202017/6/2026
SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check.
ModificadaCrítica (9.8)4.4%—Vmware Spring IntegrationOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Supply Chain Finance+431/7/202017/6/2026
Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" exploit when provided data contains malicious code for execution…
ModificadaMedia (6.5)0.97%—Oracle Insurance Accounting Analyzer15/7/202017/6/2026
Vulnerability in the Oracle Insurance Accounting Analyzer product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6-8.0.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance…
ModificadaAlta (7.4)5.2%—LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+1415/7/202017/6/2026
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
ModificadaMedia (6.1)99%💥 ExploitJqueryDrupalDebian LinuxFedoraproject Fedora+6629/4/202017/6/2026
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
ModificadaAlta (7.1)1.1%—Oracle Insurance Accounting Analyzer15/4/202017/6/2026
Vulnerability in the Oracle Insurance Accounting Analyzer product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 - 8.0.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance…
ModificadaAlta (8.8)0.49%—Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication27/2/202017/6/2026
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
ModificadaAlta (7.5)3.9%—Apache KafkaOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Liquidity Management+914/1/202017/6/2026
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can…
ModificadaMedia (6.5)1.3%—Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication6/12/201917/6/2026
Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.
ModificadaMedia (6.1)1.6%—Ldap-account-manager Ldap Account ManagerDebian LinuxFedoraproject Fedora5/12/201916/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
ModificadaMedia (6.1)1.6%—Ldap-account-manager Ldap Account ManagerDebian LinuxFedoraproject Fedora5/12/201916/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.
ModificadaBaja (3.3)0.45%—Accountsservice Project AccountsserviceOpensuseDebian LinuxRedhat Enterprise Linux27/11/201916/6/2026
An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.
ModificadaAlta (7.5)1.3%—Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication26/11/201917/6/2026
Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well.
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaMedia (6.1)0.92%—Awesomemotive Easy Digital DownloadsEasydigitaldownloads Attach Accounts TO Orders23/10/201917/6/2026
The Easy Digital Downloads (EDD) Attach Accounts to Orders extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
ModificadaMedia (5.4)0.58%—Nchsoftware Express Accounts Accounting17/10/201917/6/2026
In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Sales Orders/Items/Customers/Quotes fields parameter to inject arbitrary JavaScript.
ModificadaAlta (8.8)1.3%—Cloudfoundry User Account AND Authentication26/9/201917/6/2026
CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, ultimately allowing the malicious user to gain control of UAA scopes they should…
ModificadaCrítica (9.8)1.5%—Xm-online Xm^online 2 User Account AND Authentication Server26/8/201917/6/2026
XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key.
ModificadaMedia (6.1)0.80%—Cloudfoundry User Account AND Authentication9/8/201917/6/2026
Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that contains a SCIM filter that contains malicious JavaScript, which older browsers may execute.
Orbitaley — Vulnerabilidades