Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.74% | — | Cisco Common Services Platform Collector | 27/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Common Services Platform Collector | 27/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Common Services Platform Collector | 27/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (4.8) | 0.60% | — | Commonninja Easily Generate Rest API | 9/5/2022 | 17/6/2026 | The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.9) | 1.5% | — | Xwiki Commons | 28/4/2022 | 17/6/2026 | org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the user running XWiki application server with XML External Entity Injection through… | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Commoninja Videos Sync PDF | 25/4/2022 | 17/6/2026 | The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues | |
| Modificada | Media (6.1) | 1.1% | — | Adobe ACS AEM Commons | 21/4/2022 | 17/6/2026 | ACS Commons version 5.1.x (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in /apps/acs-commons/content/page-compare.html endpoint via the a and b GET parameters. User input submitted via these parameters is not validated or sanitised. An attacker must provide a link to someone with… | |
| Modificada | Crítica (9.8) | 8.6% | 💥 Exploit | Wielebenwir Commonsbooking | 14/3/2022 | 17/6/2026 | The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection | |
| Modificada | Alta (8.8) | 54% | — | Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+22 | 18/1/2022 | 17/6/2026 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. | |
| Modificada | Crítica (9.8) | 67% | 💥 PoC | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+24 | 18/1/2022 | 17/6/2026 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or… | |
| Modificada | Alta (8.8) | 64% | — | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+22 | 18/1/2022 | 17/6/2026 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink… | |
| Modificada | Alta (8.8) | 2.3% | 💥 PoC | Jenkins Docker Commons | 12/1/2022 | 17/6/2026 | Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository. | |
| Modificada | Alta (7.4) | 2.1% | — | Apache Sling Commons Messaging Mail | 14/12/2021 | 17/6/2026 | Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "man in the middle" attacks additional server identity checks must be performed when accessing mail servers. For compatibility reasons these additional checks are disabled… | |
| Modificada | Alta (7.5) | 81% | 💥 PoC | Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+42 | 14/12/2021 | 17/6/2026 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (5.4) | 0.72% | — | Cisco Common Services Platform Collector | 19/11/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input that is… | |
| Modificada | Media (4.9) | 1.1% | — | Cisco Common Services Platform Collector | 19/11/2021 | 17/6/2026 | A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restriction of the syslog configuration. An attacker could exploit this vulnerability… | |
| Modificada | Media (4.9) | 1.1% | — | Cisco Common Services Platform Collector | 19/11/2021 | 17/6/2026 | A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to submit a SQL query through the CSPC configuration dashboard. This vulnerability is due to insufficient input validation of uploaded files. An attacker could exploit this… | |
| Modificada | Media (4.9) | 1.00% | — | Cisco Common Services Platform Collector | 4/11/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect sensitive data when responding to a… | |
| Modificada | Media (6.5) | 4.6% | — | Apache MinaOracle Banking PaymentsOracle Banking Trade Finance Process ManagementOracle Banking Treasury Management+5 | 1/11/2021 | 17/6/2026 | In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater. | |
| Modificada | Alta (8.1) | 1.1% | — | Oracle Peoplesoft Enterprise Cost Center Common Application Objects | 20/10/2021 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC… | |
| Modificada | Crítica (9.8) | 3.0% | — | Owasp Java Html SanitizerOracle Middleware Common Libraries AND ToolsOracle Primavera Unifier | 18/10/2021 | 17/6/2026 | The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements. | |
| Modificada | Alta (7.5) | 12% | — | Apache TomcatNetapp HCINetapp Management Services FOR Element SoftwareDebian Linux+14 | 14/10/2021 | 17/6/2026 | The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a… | |
| Modificada | Crítica (9.8) | 2.8% | — | Commonwl Cwlviewer | 1/10/2021 | 17/6/2026 | cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no available workarounds aside from installing… | |
| Modificada | Alta (7.5) | 3.2% | — | SAP Commoncryptolib | 14/9/2021 | 17/6/2026 | SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, this causes the SAP application to crash and has high impact on the availability of the SAP system. |