Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)11%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected,…
AnalizadaAlta (8.5)3.4%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected,…
AnalizadaMedia (6.3)5.9%—XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed…
AnalizadaAlta (8.5)4.7%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalizadaAlta (8.5)4.5%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+923/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or…
AnalizadaAlta (8.5)4.7%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalizadaAlta (8.5)4.7%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalizadaAlta (8.5)4.7%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalizadaAlta (8.5)4.7%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalizadaAlta (8.5)14%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalizadaAlta (8.5)4.1%—XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalizadaAlta (8.5)98%⚠ Explotación activaXstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalizadaAlta (8.5)16%—XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…
AnalizadaAlta (8.8)4.5%—XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user is only affected if using the version out of the box with JDK 1.7u21…
ModificadaAlta (8.8)77%—XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+1328/5/202117/6/2026
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's…
AnalizadaCrítica (9.1)82%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to…
AnalizadaCrítica (9.8)15%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security…
AnalizadaAlta (8.6)47%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1323/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed…
AnalizadaAlta (7.5)14%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security…
AnalizadaCrítica (9.8)14%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation…
AnalizadaCrítica (9.8)76%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation…
AnalizadaCrítica (9.9)72%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the…
AnalizadaCrítica (9.8)76%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1223/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation…
AnalizadaAlta (7.5)47%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1123/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information.…
AnalizadaCrítica (9.1)50%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1123/3/202117/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information.…