Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 4.1% | 💥 PoC | Netapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+41 | 7/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS. | |
| Modificada | Alta (8.1) | 17% | 💥 PoC | Netapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+39 | 7/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS. | |
| Modificada | Alta (8.1) | 4.0% | — | Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+36 | 6/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource. | |
| Modificada | Alta (8.1) | 8.8% | 💥 PoC | Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+41 | 6/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource. | |
| Modificada | Alta (8.1) | 4.2% | — | Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+41 | 6/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource. | |
| Modificada | Alta (8.1) | 4.2% | — | Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+41 | 6/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource. | |
| Modificada | Alta (8.1) | 4.2% | — | Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+41 | 6/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource. | |
| Modificada | Alta (8.1) | 8.4% | 💥 PoC | Netapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+41 | 6/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource. | |
| Modificada | Alta (8.1) | 4.1% | — | Netapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+40 | 6/1/2021 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS. | |
| Modificada | Media (6.5) | 1.0% | — | Libpulse-binding Project Libpulse-binding | 31/12/2020 | 17/6/2026 | An issue was discovered in the libpulse-binding crate before 2.5.0 for Rust. proplist::Iterator can cause a use-after-free. | |
| Analizada | Alta (8.1) | 13% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxNetapp Service Level ManagerOracle Agile Product Lifecycle Management+36 | 27/12/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl). | |
| Modificada | Alta (8.1) | 7.8% | — | Fasterxml Jackson-databindNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+22 | 17/12/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource. | |
| Modificada | Alta (8.1) | 6.3% | — | Fasterxml Jackson-databindNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+21 | 17/12/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource. | |
| Modificada | Alta (7.5) | 25% | 💥 PoC | Apache TomcatNetapp Element Plug-inNetapp Oncommand System ManagerDebian Linux+8 | 3/12/2020 | 17/6/2026 | While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead… | |
| Modificada | Alta (7.5) | 17% | — | Fasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationNetapp Service Level Manager+35 | 3/12/2020 | 25/8/2026 | A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity. | |
| Modificada | Media (4.7) | 0.39% | — | IBM ViosIBM AIXFedoraproject FedoraOracle Communications Cloud Native Core Binding Support Function+2 | 20/11/2020 | 17/6/2026 | IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296. | |
| Modificada | Alta (8.1) | 7.3% | 💥 PoC | Fasterxml Jackson-databindOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Autovue FOR Agile Product Lifecycle Management+22 | 17/9/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. | |
| Modificada | Media (5.5) | 0.23% | — | Google AndroidOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Exposure FunctionOracle Communications Cloud Native Core Policy | 17/9/2020 | 17/6/2026 | In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android… | |
| Modificada | Alta (8.1) | 7.6% | 💥 PoC | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+21 | 25/8/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP). | |
| Modificada | Media (4.3) | 3.7% | — | ISC BindNetapp Steelstore Cloud Integrated StorageCanonical Ubuntu LinuxDebian Linux+2 | 21/8/2020 | 17/6/2026 | In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these… | |
| Modificada | Alta (7.5) | 6.4% | — | ISC BindFedoraproject FedoraOpensuse LeapDebian Linux+3 | 21/8/2020 | 17/6/2026 | In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with… | |
| Modificada | Media (6.5) | 5.6% | — | ISC BindFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+4 | 21/8/2020 | 17/6/2026 | In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an… | |
| Modificada | Alta (7.5) | 3.0% | — | ISC BindOpensuse LeapCanonical Ubuntu LinuxSynology DNS Server+1 | 21/8/2020 | 17/6/2026 | In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected. | |
| Modificada | Alta (7.5) | 3.7% | — | ISC BindOpensuse LeapNetapp Steelstore Cloud Integrated StorageCanonical Ubuntu Linux | 21/8/2020 | 17/6/2026 | In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit. | |
| Modificada | Media (4.9) | 2.1% | — | ISC BindFedoraproject FedoraOpensuse LeapDebian Linux+2 | 17/6/2020 | 1/9/2026 | In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*")… |