Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.36% | — | Oracle WEB Services ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Web Services… | |
| Aplazada | Alta (8.2) | 0.34% | — | Oracle WEB Services ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Agent). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services… | |
| Modificada | Alta (8.1) | 0.39% | — | Oracle WEB Services Manager | 18/8/2026 | 22/8/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Web Services… | |
| Modificada | Crítica (9.6) | 0.36% | — | Oracle WEB Services Manager | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Services… | |
| Modificada | Crítica (9.1) | 0.43% | — | Oracle WEB Services Manager | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services… | |
| Analizada | Baja (3.7) | 0.26% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when… | |
| Analizada | Alta (8.6) | 0.43% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to. Affected versions: Spring… | |
| Analizada | Alta (8.2) | 0.39% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could… | |
| En análisis | Media (5.3) | 0.46% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote attackers in… | |
| Analizada | Media (4.8) | 0.15% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key material unless operators explicitly reconfigured the flag. Affected versions:… | |
| Analizada | Media (5.4) | 0.18% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts). Affected versions: Spring Web Services 5.0.0… | |
| Analizada | Alta (8.2) | 0.34% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks. Affected… | |
| Analizada | Crítica (9.8) | 1.0% | — | Oracle Identity ManagerOracle WEB Services Manager | 20/3/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability… | |
| Analizada | Media (6.5) | 0.33% | — | IBM Sterling Connect Direct WEB Services | 18/4/2025 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions. | |
| Analizada | Media (6.5) | 0.31% | — | IBM Sterling Connect Direct WEB Services | 18/4/2025 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Alta (7.1) | 0.27% | — | S3bubble-amazon-web-services-oembed-media-streaming-support | 11/3/2025 | 17/6/2026 | The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Alta (8.6) | 0.42% | — | Lexmark WEB ServicesAI | 21/1/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services feature of newer Lexmark devices. | |
| Analizada | Media (4.3) | 0.38% | — | IBM Sterling Connect Direct WEB Services | 19/1/2025 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP address information to authenticated users in responses that could be used in further attacks against the system. | |
| Analizada | Alta (7.5) | 0.51% | — | Restful WEB Services Project Restful WEB Services | 9/1/2025 | 17/6/2026 | Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10. | |
| Modificada | Alta (8.6) | 0.59% | — | Amazon WEB Services Redshift Java Database Connectivity Driver | 24/12/2024 | 17/6/2026 | A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30. | |
| Analizada | Media (4.3) | 1.3% | — | Apache Commons IONetapp Active IQ Unified ManagerNetapp BluexpNetapp E-series Santricity Unified Manager+4 | 3/10/2024 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0… | |
| Aplazada | Alta (7.5) | 0.43% | — | Adacore ADA WEB ServicesAI | 25/9/2024 | 17/6/2026 | An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module. | |
| Analizada | Crítica (9.8) | 0.76% | — | IBM Sterling Connect Direct WEB Services | 31/8/2024 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality. | |
| Modificada | Media (5.9) | 0.27% | — | IBM Sterling Connect Direct WEB Services | 22/8/2024 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Analizada | Alta (7.5) | 0.30% | — | IBM Sterling Connect Direct WEB Services | 22/8/2024 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. |