Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 473 respecto a la semana anterior
Críticas / altas1452▲ 235 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.85% | — | IBM Java Software Development KIT | 14/5/2024 | 17/6/2026 | The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578. | |
| Modificada | Baja (3.3) | 0.34% | — | Squareup Connect Java Software Development KIT | 3/2/2021 | 17/6/2026 | This affects all versions of package com.squareup:connect. The method prepareDownloadFilecreates creates a temporary file with the permissions bits of -rw-r--r-- on unix-like systems. On unix-like systems, the system temporary directory is shared between users. As such, the contents of the file downloaded by… | |
| Modificada | Alta (7.5) | 7.4% | — | Microsoft Java Software Development KIT | 5/3/2019 | 17/6/2026 | An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'. | |
| Modificada | Crítica (9.8) | 3.1% | — | Microsoft Java Software Development KIT | 5/3/2019 | 17/6/2026 | An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'. | |
| Modificada | Media (5.6) | 2.1% | — | Microsoft C Software Development KITMicrosoft Java Software Development KIT | 13/9/2018 | 17/6/2026 | A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure IoT SDK Spoofing Vulnerability." This affects C SDK. | |
| Modificada | Media (5.6) | 1.2% | — | Microsoft C Software Development KITMicrosoft Csharp Software Development KITMicrosoft Java Software Development KIT | 9/5/2018 | 17/6/2026 | A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK. |