Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3037▲ 502 respecto a la semana anterior
Críticas / altas1448▲ 249 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 158 respecto a la semana anterior
–

64 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)38%—Fasterxml Jackson-databindDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+176/2/201817/6/2026
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
ModificadaCrítica (9.8)8.4%—Fasterxml Jackson-databindDebian LinuxRedhat Openshift Container PlatformRedhat Satellite+206/2/201817/6/2026
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting…
ModificadaAlta (8.1)7.0%—Fasterxml Jackson-databindDebian LinuxRedhat Openshift Container PlatformRedhat Virtualization+522/1/201817/6/2026
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
ModificadaAlta (8.3)3.3%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+2018/1/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaAlta (7.5)0.49%—Oracle JDKOracle JRERedhat SatelliteNetapp Active IQ Unified Manager+1618/1/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks…
ModificadaMedia (4.7)2.5%—Oracle JDKOracle JRERedhat SatelliteNetapp Active IQ Unified Manager+1618/1/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaCrítica (9.8)50%—Fasterxml Jackson-databindDebian LinuxRedhat Jboss Enterprise Application PlatformRedhat Openshift Container Platform+410/1/201817/6/2026
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that…
ModificadaAlta (7.5)3.2%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+2519/10/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise…
ModificadaMedia (5.3)3.3%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+2519/10/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaMedia (6.2)0.75%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+2519/10/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the…
ModificadaMedia (5.3)16%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+2619/10/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access…
ModificadaMedia (5.3)3.3%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+2519/10/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affected are Java SE: 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise…
ModificadaMedia (5.3)3.3%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+2519/10/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaMedia (5.3)3.3%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+2519/10/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaMedia (5.3)3.1%—Oracle JDKOracle JREDebian LinuxRedhat Satellite+2519/10/201717/6/2026
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaCrítica (9.6)3.0%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+2519/10/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaBaja (3.1)2.4%—Oracle JDKOracle JREOracle JrockitDebian Linux+2619/10/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network…
ModificadaAlta (7.1)8.8%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+2219/10/201717/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u144 and 9. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaMedia (4)2.2%—Oracle JDKOracle JREOracle JrockitDebian Linux+2619/10/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access…
ModificadaMedia (6.1)1.5%—Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+1719/10/201717/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Javadoc). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java SE. Successful attacks require human…
ModificadaCrítica (9.6)3.1%—Oracle JDKOracle JREDebian LinuxRedhat Satellite+2519/10/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise…
ModificadaMedia (5.3)3.3%—Oracle JDKOracle JREOracle JrockitDebian Linux+2619/10/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network…
ModificadaMedia (6.8)2.6%—Oracle JDKOracle JREDebian LinuxRedhat Enterprise Linux Desktop+2419/10/201717/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Smart Card IO). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks…
AnalizadaAlta (8.1)100%⚠ Explotación activaApache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+544/10/201725/8/2026
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP…
AnalizadaAlta (8.1)100%⚠ Explotación activaApache TomcatNetapp 7-mode Transition ToolNetapp Oncommand BalanceNetapp Oncommand Shift+1819/9/20176/8/2026
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed…