Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 1.0% | — | Jboss MOD ClusterAI | 19/8/2026 | 20/8/2026 | A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" header but without the "Date:", "Digest:", and "Sequence:" headers triggers a NullPointerException in verifyDigest() that is not caught by… | |
| Modificada | Alta (7.5) | 2.7% | — | Redhat MOD ClusterRedhat Enterprise Linux | 12/4/2017 | 17/6/2026 | Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9. | |
| Modificada | Media (4.3) | 1.8% | — | Redhat MOD Cluster | 24/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the manager web interface in mod_cluster before 1.3.2.Alpha1 allows remote attackers to inject arbitrary web script or HTML via a crafted MCMP message. | |
| Modificada | Media (4.3) | 2.6% | — | Redhat Jboss Enterprise Application PlatformRedhat MOD Cluster | 22/10/2012 | 16/6/2026 | mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context… |