Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)2.6%—Apache ANTOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Trade Finance+3214/7/202125/8/2026
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR…
ModificadaMedia (5.5)2.5%—Apache ANTOracle Agile Product Lifecycle ManagementOracle Banking Trade FinanceOracle Banking Treasury Management+2814/7/202125/8/2026
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
ModificadaAlta (8.2)13%—Apache BatikFedoraproject FedoraOracle Agile Engineering Data ManagementOracle Banking Apis+1824/2/202117/6/2026
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
ModificadaCrítica (9.8)5.5%—Oracle Enterprise RepositoryOracle Weblogic Server20/1/202117/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful…
ModificadaAlta (7.5)11%—Apache BatikOracle API GatewayOracle Business IntelligenceOracle Communications Application Session Controller+1412/11/202017/6/2026
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
ModificadaAlta (7.5)8.0%—Apache ANTGradleFedoraproject FedoraOracle Agile Engineering Data Management+331/10/202017/6/2026
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still…
ModificadaCrítica (9.8)49%—Apache ActivemqOracle Communications Diameter Signaling RouterOracle Communications Element ManagerOracle Communications Session Report Manager+310/9/202017/6/2026
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack:…
ModificadaAlta (7.5)4.5%—Apache CamelOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base PlatformOracle Enterprise Repository8/7/202017/6/2026
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
ModificadaMedia (6.1)7.1%—Apache ActivemqOracle Communications Diameter Signaling RouterOracle Communications Element ManagerOracle Communications Session Report Manager+314/5/202017/6/2026
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
ModificadaMedia (6.3)1.8%—Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+4614/5/202017/6/2026
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an…
ModificadaMedia (5.5)1.00%—Apache POIOracle Application Testing SuiteOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+2323/10/201917/6/2026
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
ModificadaCrítica (9.8)14%—Oracle Application Testing SuiteOracle Banking Enterprise CollectionsOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+1816/10/201917/6/2026
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and…
ModificadaAlta (7.5)9.8%—Apache CamelOracle Enterprise Data QualityOracle Enterprise Manager Base PlatformOracle Flexcube Private Banking+128/5/201917/6/2026
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
ModificadaAlta (7.5)12%—Apache ActivemqNetapp E-series Santricity WEB ServicesOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base Platform+428/3/201917/6/2026
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
ModificadaAlta (7.5)2.9%—Oracle Banking PlatformOracle Business Process Management SuiteOracle Communications Converged Application ServerOracle Communications Webrtc Session Controller+517/10/201817/6/2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.…
ModificadaAlta (7.4)7.0%—Apache ActivemqOracle Enterprise RepositoryOracle Flexcube Private Banking10/9/201817/6/2026
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.
ModificadaCrítica (9.8)4.8%—Bouncycastle Bc-javaNetapp Oncommand Workflow AutomationOpensuse LeapOracle API Gateway+209/7/201817/6/2026
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an…
ModificadaAlta (7.5)3.6%—Bouncycastle Bc-javaBouncycastle Fips Java APIDebian LinuxOracle API Gateway+165/6/201817/6/2026
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA…
ModificadaCrítica (9.8)19%—Apache BatikDebian LinuxCanonical Ubuntu LinuxOracle Business Intelligence+1724/5/201817/6/2026
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
ModificadaAlta (8.8)2.5%—Pivotal Software Spring SecurityVmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+3811/5/201825/8/2026
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
ModificadaAlta (8.2)1.9%—Oracle Enterprise Repository8/8/201717/6/2026
Vulnerability in the Oracle Enterprise Repository component of Oracle Fusion Middleware (subcomponent: Web Interface). Supported versions that are affected are 11.1.1.7.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise…