Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3042▲ 473 respecto a la semana anterior
Críticas / altas1452▲ 235 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.85%—IBM Java Software Development KIT14/5/202417/6/2026
The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578.
ModificadaBaja (3.3)0.34%—Squareup Connect Java Software Development KIT3/2/202117/6/2026
This affects all versions of package com.squareup:connect. The method prepareDownloadFilecreates creates a temporary file with the permissions bits of -rw-r--r-- on unix-like systems. On unix-like systems, the system temporary directory is shared between users. As such, the contents of the file downloaded by…
ModificadaAlta (7.5)7.4%—Microsoft Java Software Development KIT5/3/201917/6/2026
An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'.
ModificadaCrítica (9.8)3.1%—Microsoft Java Software Development KIT5/3/201917/6/2026
An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'.
ModificadaMedia (5.6)2.1%—Microsoft C Software Development KITMicrosoft Java Software Development KIT13/9/201817/6/2026
A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure IoT SDK Spoofing Vulnerability." This affects C SDK.
ModificadaMedia (5.6)1.2%—Microsoft C Software Development KITMicrosoft Csharp Software Development KITMicrosoft Java Software Development KIT9/5/201817/6/2026
A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK.