Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 1.6% | — | Redhat Build OF KeycloakRedhat Jboss Middleware Text-only AdvisoriesRedhat KeycloakRedhat Migration Toolkit FOR Applications+6 | 17/4/2024 | 4/8/2026 | A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that… | |
| Modificada | Alta (8.1) | 1.4% | — | QuarkusRedhat Build OF OptaplannerRedhat Build OF QuarkusRedhat Decision Manager+8 | 20/9/2023 | 4/8/2026 | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and… | |
| Modificada | Alta (8.8) | 1.0% | — | Redhat Decision ManagerRedhat DroolsRedhat Jboss Middleware Text-only AdvisoriesRedhat Process Automation | 11/9/2023 | 17/6/2026 | A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server. | |
| Modificada | Media (6.5) | 2.1% | 💥 PoC | Hibernate ORMRedhat Build OF QuarkusRedhat Decision ManagerRedhat Fuse+6 | 6/7/2020 | 17/6/2026 | A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or… | |
| Modificada | Media (5.9) | 1.8% | — | Apache CXFApache Wss4jRedhat Jboss Business Rules Management SystemRedhat Jboss Enterprise Application Platform+6 | 11/3/2020 | 16/6/2026 | The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack. | |
| Modificada | Alta (7.5) | 11% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraApache Drill+14 | 30/7/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath. | |
| Modificada | Media (5.4) | 4.8% | — | Apache KafkaRedhat Jboss Middleware Text-only AdvisoriesOracle DatabaseOracle Primavera P6 Enterprise Project Portfolio Management+1 | 26/7/2018 | 17/6/2026 | In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss. | |
| Modificada | Alta (7.5) | 11% | — | NettyRedhat Jboss Data GridRedhat Jboss Middleware Text-only AdvisoriesApache Cassandra | 13/4/2017 | 17/6/2026 | handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop). | |
| Analizada | Crítica (9.8) | 93% | ⚠ Explotación activa💥 Exploit | Apache AuroraApache ShiroRedhat FuseRedhat Jboss Middleware Text-only Advisories | 7/6/2016 | 17/6/2026 | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter. |