Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)7.8%—Fasterxml Jackson-databindNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+2217/12/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
ModificadaAlta (8.1)6.3%—Fasterxml Jackson-databindNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+2117/12/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
ModificadaCrítica (9.8)7.3%—Dom4j Project Dom4jOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Banking Platform+341/5/202025/8/2026
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
ModificadaBaja (3.7)8.1%💥 PoCApache Log4jOracle Communications Application Session ControllerOracle Communications Billing AND Revenue ManagementOracle Communications Eagle FTP Table Base Retrieval+4227/4/202017/6/2026
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
AnalizadaAlta (8.8)6.3%💥 PoCFasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2831/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
AnalizadaAlta (8.8)3.6%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2731/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
ModificadaAlta (8.8)3.6%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2726/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
ModificadaAlta (8.8)3.6%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2726/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
ModificadaAlta (8.8)8.0%💥 PoCFasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2718/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
ModificadaAlta (8.8)3.1%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2718/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
AnalizadaCrítica (9.8)4.6%—Fasterxml Jackson-databindNetapp Active IQ Unified ManagerDebian LinuxOracle Agile Product Lifecycle Management+272/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
ModificadaMedia (5.3)2.4%—Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications BRM - Elastic Charging EngineOracle Communications Diameter Signaling Router+2317/1/202017/6/2026
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and…
ModificadaAlta (7.5)89%💥 PoCVmware Spring FrameworkOracle Application Testing SuiteOracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Policy+2917/1/202017/6/2026
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaMedia (5.5)1.00%—Apache POIOracle Application Testing SuiteOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+2323/10/201917/6/2026
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
ModificadaAlta (7.5)9.2%—Vmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Communications BRM - Elastic Charging EngineOracle Communications Converged Application Server - Service Controller+3618/10/201825/8/2026
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an…
ModificadaCrítica (9.8)19%—Apache BatikDebian LinuxCanonical Ubuntu LinuxOracle Business Intelligence+1724/5/201817/6/2026
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
ModificadaAlta (8.8)5.1%—Oracle DocumakerOracle Enterprise Manager OPS CenterOracle Health Sciences Information ManagerOracle Healthcare Master Person Index+721/7/201617/6/2026
Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index…
Orbitaley — Vulnerabilidades