Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2640▼ 268 respecto a la semana anterior
Críticas / altas1348▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 468 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (3.7)0.23%—Gstreamer WebrtcbinAI7/7/20268/7/2026
A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. An attacker with the…
AplazadaAlta (8.7)0.40%—Elixir WebrtcAI14/5/202617/6/2026
Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments,…
ModificadaMedia (6)0.20%—Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+1212/7/202317/6/2026
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected…
AnalizadaAlta (8.8)70%⚠ Explotación activaGoogle ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraWebkitgtk+828/7/20224/8/2026
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (5.9)100%—Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+11218/12/202125/8/2026
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j…
ModificadaMedia (5.3)0.68%—Webrtc Project Webrtc18/3/202117/6/2026
Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerConnectionState was set to failed, but a user could ignore that and continue to use the PeerConnection. )A WebRTC implementation shouldn't allow the user to continue if verification has failed.)
ModificadaCrítica (9.8)1.6%—Intel Open Webrtc Toolkit13/11/202017/6/2026
Insufficient control flow management in the Open WebRTC Toolkit before version 4.3.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaMedia (6.1)99%—JqueryDrupalDebian LinuxFedoraproject Fedora+6629/4/202017/6/2026
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
ModificadaMedia (6.1)2.2%—Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaMedia (6.1)87%—JqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaAlta (7.5)2.9%—Oracle Banking PlatformOracle Business Process Management SuiteOracle Communications Converged Application ServerOracle Communications Webrtc Session Controller+517/10/201817/6/2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.…
ModificadaCrítica (9.8)4.8%—Bouncycastle Bc-javaNetapp Oncommand Workflow AutomationOpensuse LeapOracle API Gateway+209/7/201817/6/2026
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an…
ModificadaAlta (7.5)2.0%—Webrtc-experiment Fbr-client7/6/201817/6/2026
fbr-client sends files through sockets via socket.io and webRTC. fbr-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)3.6%—Bouncycastle Bc-javaBouncycastle Fips Java APIDebian LinuxOracle API Gateway+165/6/201817/6/2026
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA…
ModificadaAlta (8.1)2.1%—Webrtc-native1/6/201817/6/2026
webrtc-native uses WebRTC from chromium project. webrtc-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or…
ModificadaCrítica (9.8)19%—Apache BatikDebian LinuxCanonical Ubuntu LinuxOracle Business Intelligence+1724/5/201817/6/2026
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
ModificadaCrítica (9.1)5.9%—Debian LinuxCanonical Ubuntu LinuxHaxx CurlRedhat Enterprise Linux Desktop+524/5/201817/6/2026
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl <…
ModificadaCrítica (9.1)9.0%—Debian LinuxCanonical Ubuntu LinuxHaxx CurlRedhat Enterprise Linux Desktop+514/3/201817/6/2026
A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage
ModificadaAlta (7.5)9.2%—Debian LinuxCanonical Ubuntu LinuxHaxx CurlRedhat Enterprise Linux Desktop+514/3/201817/6/2026
A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service
ModificadaCrítica (9.8)12%—Debian LinuxCanonical Ubuntu LinuxHaxx CurlRedhat Enterprise Linux Desktop+514/3/201817/6/2026
A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.
ModificadaMedia (6.1)30%—JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+4318/1/201817/6/2026
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
ModificadaMedia (6.3)1.6%—Oracle Communications Webrtc Session Controller19/10/201717/6/2026
Vulnerability in the Oracle Communications WebRTC Session Controller component of Oracle Communications Applications (subcomponent: Security (Gson)). Supported versions that are affected are 7.0, 7.1 and 7.2. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols…
ModificadaCrítica (9.8)90%—Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+7517/4/201717/6/2026
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
ModificadaMedia (5.5)1.3%—Mozilla FirefoxWebrtc Project Webrtc13/3/201617/6/2026
Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
ModificadaMedia (6.3)1.2%—Webrtc Project WebrtcMozilla Firefox13/3/201617/6/2026
Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.