Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
–

210 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.4)0.36%—Oracle WEB Services ManagerAI15/9/202621/9/2026
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Web Services…
AplazadaAlta (8.2)0.34%—Oracle WEB Services ManagerAI15/9/202621/9/2026
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Agent). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services…
ModificadaAlta (8.1)0.39%—Oracle WEB Services Manager18/8/202622/8/2026
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Web Services…
ModificadaCrítica (9.6)0.36%—Oracle WEB Services Manager18/8/202624/8/2026
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Services…
ModificadaCrítica (9.1)0.43%—Oracle WEB Services Manager18/8/202620/8/2026
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services…
AnalizadaBaja (3.7)0.26%—Broadcom Spring WEB Services11/6/20264/9/2026
Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when…
AnalizadaAlta (8.6)0.43%—Broadcom Spring WEB Services11/6/20264/9/2026
When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to. Affected versions: Spring…
AnalizadaAlta (8.2)0.39%—Broadcom Spring WEB Services11/6/20264/9/2026
Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could…
En análisisMedia (5.3)0.46%—Broadcom Spring WEB Services11/6/20264/9/2026
Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote attackers in…
AnalizadaMedia (4.8)0.15%—Broadcom Spring WEB Services11/6/20264/9/2026
Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key material unless operators explicitly reconfigured the flag. Affected versions:…
AnalizadaMedia (5.4)0.18%—Broadcom Spring WEB Services11/6/20264/9/2026
X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts). Affected versions: Spring Web Services 5.0.0…
AnalizadaAlta (8.2)0.34%—Broadcom Spring WEB Services11/6/20264/9/2026
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks. Affected…
AnalizadaCrítica (9.8)1.0%—Oracle Identity ManagerOracle WEB Services Manager20/3/202617/6/2026
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability…
AnalizadaMedia (6.5)0.33%—IBM Sterling Connect Direct WEB Services18/4/202517/6/2026
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.
AnalizadaMedia (6.5)0.31%—IBM Sterling Connect Direct WEB Services18/4/202517/6/2026
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.
AnalizadaAlta (7.1)0.27%—S3bubble-amazon-web-services-oembed-media-streaming-support11/3/202517/6/2026
The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaAlta (8.6)0.42%—Lexmark WEB ServicesAI21/1/202517/6/2026
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services feature of newer Lexmark devices.
AnalizadaMedia (4.3)0.38%—IBM Sterling Connect Direct WEB Services19/1/202517/6/2026
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP address information to authenticated users in responses that could be used in further attacks against the system.
AnalizadaAlta (7.5)0.51%—Restful WEB Services Project Restful WEB Services9/1/202517/6/2026
Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10.
ModificadaAlta (8.6)0.59%—Amazon WEB Services Redshift Java Database Connectivity Driver24/12/202417/6/2026
A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.
AnalizadaMedia (4.3)1.3%—Apache Commons IONetapp Active IQ Unified ManagerNetapp BluexpNetapp E-series Santricity Unified Manager+43/10/202417/6/2026
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0…
AplazadaAlta (7.5)0.43%—Adacore ADA WEB ServicesAI25/9/202417/6/2026
An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.
AnalizadaCrítica (9.8)0.76%—IBM Sterling Connect Direct WEB Services31/8/202417/6/2026
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.
ModificadaMedia (5.9)0.27%—IBM Sterling Connect Direct WEB Services22/8/202417/6/2026
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
AnalizadaAlta (7.5)0.30%—IBM Sterling Connect Direct WEB Services22/8/202417/6/2026
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.