Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 2.2% | — | Redhat XnioRedhat Jboss BrmsRedhat Jboss Data GridRedhat Jboss Data Virtualization+10 | 2/6/2021 | 17/6/2026 | A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final. | |
| Modificada | Alta (7.5) | 0.91% | — | Redhat Jboss BrmsRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss Operations Network+2 | 23/1/2020 | 16/6/2026 | EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation. | |
| Modificada | Alta (7.5) | 8.9% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraOracle JD Edwards Enterpriseone Tools+7 | 21/3/2019 | 17/6/2026 | An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service… | |
| Modificada | Alta (7.5) | 7.2% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraOracle JD Edwards Enterpriseone Tools+7 | 21/3/2019 | 17/6/2026 | An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access,… | |
| Modificada | Crítica (9.8) | 11% | — | Fasterxml Jackson-databindDebian LinuxOracle Business Process Management SuiteOracle Primavera P6 Enterprise Project Portfolio Management+8 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 11% | — | Fasterxml Jackson-databindDebian LinuxOracle Business Process Management SuiteOracle Primavera P6 Enterprise Project Portfolio Management+8 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 11% | — | Fasterxml Jackson-databindDebian LinuxOracle Business Process Management SuiteOracle Primavera P6 Enterprise Project Portfolio Management+8 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization. | |
| Modificada | Media (6.5) | 4.0% | — | Redhat Jboss BrmsRedhat Jboss Drools | 10/9/2018 | 17/6/2026 | Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restrictions and retrieve arbitrary files from the affected host. |