Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2566▼ 354 respecto a la semana anterior
Críticas / altas1319▲ 46 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)76▼ 451 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)100%⚠ Explotación activaVmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+341/4/202217/6/2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to…
AnalizadaCrítica (9.8)100%⚠ Explotación activaVmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+241/4/202217/6/2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
ModificadaAlta (7.5)4.9%—Fasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+3211/3/202217/6/2026
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
ModificadaMedia (5.5)4.8%—Vmware Spring Cloud GatewayOracle Commerce Guided SearchOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Console+24/3/202217/6/2026
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.
AnalizadaCrítica (10)98%⚠ Explotación activaVmware Spring Cloud GatewayOracle Commerce Guided SearchOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Console+63/3/202217/6/2026
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
ModificadaAlta (8.8)4.1%—Cyrusimap Cyrus-saslDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+424/2/202217/6/2026
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
ModificadaCrítica (9.8)65%—H2database H2Debian LinuxOracle Communications Cloud Native Core Console19/1/202217/6/2026
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
ModificadaMedia (5.5)1.7%—Google-protobufGoogle Protobuf-javaGoogle Protobuf-kotlinOracle Communications Cloud Native Core Console+310/1/202217/6/2026
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend…
ModificadaMedia (4.3)0.85%—Vmware Spring FrameworkOracle Communications Cloud Native Core ConsoleOracle Communications Cloud Native Core Service Communication Proxy10/1/202217/6/2026
In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring…
ModificadaMedia (5.9)100%—Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+11218/12/202125/8/2026
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j…
ModificadaMedia (6.5)4.6%—Apache MinaOracle Banking PaymentsOracle Banking Trade Finance Process ManagementOracle Banking Treasury Management+51/11/202117/6/2026
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
ModificadaMedia (4.3)1.4%—Vmware Spring FrameworkNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Metrocluster Tiebreaker+428/10/202117/6/2026
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
ModificadaMedia (5.9)7.5%—Oracle Communications Cloud Native Core ConsoleOracle Communications Cloud Native Core Network Slice Selection FunctionOracle Communications Cloud Native Core PolicyOracle Communications Cloud Native Core Security Edge Protection Proxy+220/10/202117/6/2026
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this…
ModificadaMedia (5.9)3.0%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Cloud Backup+2229/9/202117/6/2026
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and…
ModificadaAlta (7.5)4.5%—Haxx CurlDebian LinuxFedoraproject FedoraNetapp Cloud Backup+2529/9/202117/6/2026
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly…
ModificadaAlta (7.4)50%—OpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+2824/8/202117/6/2026
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a…
ModificadaMedia (6.5)3.0%—Apache SshdOracle Banking PaymentsOracle Banking Trade FinanceOracle Banking Treasury Management+512/7/202117/6/2026
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
ModificadaMedia (5.9)2.2%—Redhat XnioRedhat Jboss BrmsRedhat Jboss Data GridRedhat Jboss Data Virtualization+102/6/202117/6/2026
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
ModificadaMedia (5.9)4.9%—NettyDebian LinuxNetapp Oncommand API ServicesNetapp Oncommand Workflow Automation+1430/3/202117/6/2026
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not…
ModificadaMedia (5.3)1.4%—Redhat ResteasyNetapp Oncommand InsightQuarkusOracle Communications Cloud Native Core Console26/3/202117/6/2026
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this…
ModificadaAlta (7.4)2.9%—Hibernate ORMDebian LinuxQuarkusOracle Communications Cloud Native Core Console+12/12/202017/6/2026
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly…
ModificadaMedia (6.1)2.2%—Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaAlta (7.3)28%—Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+5620/8/201925/8/2026
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.