Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

523 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)1.0%—Redhat Jboss Portal2/1/202017/6/2026
It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, under high-concurrency scenarios or scenarios where SOAP messages take long to execute, it was possible for an unauthenticated remote attacker to gain privileged information…
ModificadaMedia (6.5)0.78%—Redhat Jboss Enterprise Application Platform2/1/202017/6/2026
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality,…
ModificadaCrítica (9.8)2.0%—InfinispanRedhat Jboss Data Grid2/1/202017/6/2026
A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.
ModificadaMedia (6.1)4.0%💥 PoCSmartbear Swagger-uiRedhat Jboss FuseRedhat Openshift20/12/201917/6/2026
swagger-ui has XSS in key names
ModificadaAlta (7.5)8.0%—Cyrusimap Cyrus-saslDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+1519/12/201917/6/2026
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
ModificadaAlta (7.8)0.29%—Redhat Jboss Application ServerRedhat Jboss Enterprise Application Platform18/12/201916/6/2026
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.
ModificadaAlta (8.1)1.5%—Redhat EdeployRedhat Jboss Enterprise WEB Server15/12/201917/6/2026
eDeploy has tmp file race condition flaws
ModificadaCrítica (9.8)2.4%—Redhat EdeployRedhat Jboss Enterprise WEB Server15/12/201917/6/2026
eDeploy has RCE via cPickle deserialization of untrusted data
ModificadaMedia (6.1)0.65%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Portal11/12/201917/6/2026
JBossWeb Bayeux has reflected XSS
ModificadaMedia (6.1)0.77%💥 PoCRedhat Jboss Keycloak10/12/201917/6/2026
JBoss KeyCloak: XSS in login-status-iframe.html
ModificadaBaja (3.3)0.32%—Redhat Jboss Community Application ServerRedhat Jboss Enterprise WEB Server6/12/201916/6/2026
An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
ModificadaMedia (6.5)1.3%—Redhat Jboss Application Server26/11/201916/6/2026
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a…
ModificadaMedia (5.4)1.1%—Redhat Jboss Application Server26/11/201916/6/2026
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment…
ModificadaAlta (8.8)3.1%—InfinispanRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+325/11/201917/6/2026
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
ModificadaCrítica (9.8)2.8%—Redhat EdeployRedhat Jboss Enterprise WEB Server21/11/201917/6/2026
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
ModificadaAlta (7.5)17%💥 PoCFasterxml Jackson-mapper-aslRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseDebian Linux+118/11/201917/6/2026
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
ModificadaMedia (4.3)0.46%—Redhat KeycloakRedhat Jboss Enterprise WEB Server13/11/201917/6/2026
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
ModificadaMedia (6.1)0.85%—Redhat Jboss Business Rules Management System12/11/201916/6/2026
JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter.
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaMedia (6.5)0.87%—Redhat Jboss Operations Network8/11/201916/6/2026
In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.
ModificadaAlta (7.1)0.31%—Redhat RHQ Mongo DB Drift ServerRedhat Jboss Operations Network4/11/201916/6/2026
An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files.
ModificadaMedia (6.1)0.65%—Redhat Jboss Aerogear4/11/201917/6/2026
JBoss AeroGear has reflected XSS via the password field
ModificadaCrítica (9.8)89%💥 ExploitApache StrutsRedhat Jboss Enterprise WEB Server1/11/201916/6/2026
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
ModificadaAlta (8)0.53%—Redhat Jboss Operations Network30/10/201916/6/2026
A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.
ModificadaAlta (7.5)6.4%—Apache ThriftRedhat Jboss Enterprise Application PlatformOracle Communications Cloud Native Core Network Slice Selection Function29/10/201917/6/2026
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
Orbitaley — Vulnerabilidades