Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 298 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.55%—AmuleAI14/7/202615/7/2026
Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via the OP_SERVERMESSAGE Handler.
AnalizadaMedia (5.3)0.21%—Salesforce Mulesoft Anypoint Code Builder4/11/202517/6/2026
Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before 1.12.1
AnalizadaMedia (5.3)0.22%—Salesforce Mulesoft Anypoint Code Builder4/11/202517/6/2026
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before 1.12.1.
AnalizadaMedia (6.5)0.20%—Salesforce Mulesoft Anypoint Code Builder4/11/202517/6/2026
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.This issue affects Mulesoft Anypoint Code Builder: before 1.11.6.
ModificadaCrítica (9.1)0.99%—Broadcom Emulex HBA Manager12/11/202117/6/2026
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a vulnerability in the remote firmware download feature that could allow a user to place or replace an arbitrary file on the remote host. In non-secure mode, the user is…
ModificadaCrítica (9.8)2.4%—Broadcom Emulex HBA Manager12/11/202117/6/2026
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote firmware download feature that could allow remote unauthenticated users to perform various attacks. In non-secure mode, the…
ModificadaAlta (7.5)1.00%—Broadcom Emulex HBA Manager12/11/202117/6/2026
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, could allow a user to retrieve an arbitrary file from a remote host with the GetDumpFile command. In non-secure mode, the user is unauthenticated.
ModificadaCrítica (9.8)1.3%—Broadcom Emulex HBA ManagerBroadcom ONE Command Manager3/11/202117/6/2026
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote GetDumpFile command that could allow a user to attempt various attacks. In non-secure mode, the user is unauthenticated
ModificadaAlta (7.5)1.1%—Salesforce Mule5/8/202117/6/2026
XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.
ModificadaCrítica (9.8)1.2%—Salesforce Mule26/3/202117/6/2026
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4.x runtime released before February 2, 2021.
ModificadaCrítica (9.8)1.0%—Salesforce Mule26/3/202117/6/2026
MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before February 2, 2021.
ModificadaCrítica (9.8)2.0%—Salesforce Mule26/3/202117/6/2026
MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Versions affected: Mule 4.1.x and 4.2.x runtime released before February 2, 2021.
ModificadaAlta (7.5)1.2%—Mulesoft Mule Runtime29/5/202017/6/2026
A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.
ModificadaCrítica (9.8)1.4%—Mulesoft Aplkit27/3/202017/6/2026
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
ModificadaCrítica (9.8)2.3%—Mulesoft API GatewayMulesoft Mule Runtime2/12/201917/6/2026
Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.
ModificadaCrítica (9.8)5.1%—Mulesoft Mule Runtime16/10/201917/6/2026
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections
ModificadaAlta (7.5)3.0%—Mulesoft API GatewayMulesoft Mule Runtime30/8/201917/6/2026
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to…
ModificadaMedia (6.5)8.9%—Mulesoft Mule Enterprise Management Console20/11/201417/6/2026
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. NOTE: this issue was originally reported for ESB Runtime 3.5.1, but…
ModificadaMedia (5)1.4%—Aemuleplus Emule PlusEmuleplus Emule Plus29/4/200916/6/2026
The logging feature in eMule Plus before 1.2e allows remote attackers to cause a denial of service (infinite loop) via unspecified attack vectors.
ModificadaMedia (6.8)1.5%—Amule27/4/200916/6/2026
Incomplete blacklist vulnerability in DownloadListCtrl.cpp in amule 2.2.4 allows remote attackers to conduct argument injection attacks into a command for mplayer via a crafted filename.
ModificadaAlta (7.5)1.4%—Emule X RAY29/5/200816/6/2026
Unspecified vulnerability in the web server in eMule X-Ray before 1.4 allows remote attackers to trigger memory corruption via unknown attack vectors.
ModificadaAlta (9.3)1.4%—Sourceforge Emule X-ray29/5/200816/6/2026
Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.
ModificadaAlta (10)1.6%—Emule Plus28/5/200816/6/2026
Unspecified vulnerability in eMule Plus before 1.2d has unknown impact and attack vectors related to "staticservers.dat processing."
ModificadaMedia (5)1.7%—Amule31/5/200616/6/2026
Multiple unspecified vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to read arbitrary image, HTML, or PHP files via unknown vectors, probably related to directory traversal.
ModificadaMedia (5)1.4%—Amule31/5/200616/6/2026
Unspecified "information leakage" vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to access arbitrary images, including dynamically generated images, via unknown vectors.