Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)100%💥 PoCApache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+11218/12/202125/8/2026
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j…
ModificadaAlta (7.5)2.4%—Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+10721/7/202125/8/2026
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks…
ModificadaMedia (5.5)0.50%—SqliteOracle Communications Network Charging AND ControlEnterprise Manager FOR Oracle DatabaseOracle JD Edwards Enterpriseone Tools+323/3/202117/6/2026
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system…
AnalizadaAlta (8.1)5.0%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+417/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
ModificadaAlta (8.1)4.1%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+417/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
ModificadaAlta (8.1)4.1%💥 PoCNetapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+417/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
ModificadaAlta (8.1)17%💥 PoCNetapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+397/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
ModificadaAlta (8.1)4.0%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+366/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.
ModificadaAlta (8.1)8.8%💥 PoCFasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+416/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.
ModificadaAlta (8.1)4.2%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+416/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.
ModificadaAlta (8.1)4.2%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+416/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.
ModificadaAlta (8.1)4.2%—Fasterxml Jackson-databindNetapp Cloud BackupNetapp Service Level ManagerDebian Linux+416/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.
ModificadaAlta (8.1)8.4%💥 PoCNetapp Cloud BackupNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+416/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
ModificadaAlta (8.1)4.1%—Netapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+406/1/202125/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
AnalizadaAlta (8.1)13%💥 PoCFasterxml Jackson-databindDebian LinuxNetapp Service Level ManagerOracle Agile Product Lifecycle Management+3627/12/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
ModificadaAlta (7.5)17%—Fasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationNetapp Service Level Manager+353/12/202025/8/2026
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
ModificadaMedia (5.5)1.0%—SqliteCanonical Ubuntu LinuxApple IcloudApple Ipados+1227/6/202017/6/2026
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
ModificadaAlta (7.5)4.4%—SqliteFedoraproject FedoraDebian LinuxOracle Communications Messaging Server+86/6/202017/6/2026
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
ModificadaMedia (5.5)0.57%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+827/5/202017/6/2026
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
ModificadaMedia (5.5)0.62%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+1427/5/202017/6/2026
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
ModificadaAlta (7)1.0%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+1527/5/202017/6/2026
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
ModificadaMedia (5.5)1.0%—SqliteDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+1124/5/202017/6/2026
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
ModificadaCrítica (9.8)7.6%—SqliteNetapp Ontap Select Deploy Administration UtilityOracle Communications Network Charging AND ControlOracle Enterprise Manager OPS Center+89/4/202017/6/2026
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
ModificadaAlta (7.5)4.3%—SqliteNetapp Ontap Select Deploy Administration UtilityDebian LinuxCanonical Ubuntu Linux+149/4/202017/6/2026
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
ModificadaAlta (8.1)5.8%—Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated Storage+147/4/202017/6/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
Orbitaley — Vulnerabilidades