Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
3872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.18% | — | Apache StrutsAI | 5/10/2026 | 6/10/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the application-wide text provider is used by concurrently served requests without isolation,… | |
| Pendiente de análisis | Media (6.5) | 0.19% | — | Apache StrutsAI | 5/10/2026 | 6/10/2026 | Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single request can cause the server to allocate memory in proportion to its size, exhausting the Java heap and denying service to… | |
| Pendiente de análisis | Alta (7.5) | 0.28% | — | Apache StrutsAI | 5/10/2026 | 6/10/2026 | Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the… | |
| Pendiente de análisis | Crítica (9.8) | 0.36% | — | Apache StrutsAI | 5/10/2026 | 6/10/2026 | Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts… | |
| Aplazada | Alta (8.8) | 0.22% | — | Apache OpenofficeAI | 2/10/2026 | 6/10/2026 | A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can… | |
| Aplazada | Alta (7) | 0.28% | — | Apache Traffic ServerAI | 2/10/2026 | 2/10/2026 | Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x… | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.41% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.41% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift nodejs and D lang bindings. Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the… | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Uncontrolled Recursion vulnerability in Apache Thrift go bindings. Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again instead of looping. A peer produces such a frame for 4 bytes in `TFramedTransport` (a declared size of… | |
| Aplazada | Crítica (9.2) | 0.38% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.26% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thrift_protocol extension, and… | |
| Aplazada | Alta (8.7) | 0.29% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Media (6.9) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 3/10/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Access of Uninitialized Pointer vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.26% | — | Apache ThriftAI | 2/10/2026 | 3/10/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |