Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.2) | 0.43% | — | Apache Activemq ArtemisAI | 28/9/2026 | 29/9/2026 | Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated… | |
| Analizada | Crítica (9.1) | 0.86% | — | Apache Artemis | 10/9/2026 | 16/9/2026 | A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0… | |
| Analizada | Crítica (9.8) | 1.1% | 💥 PoC | Apache Artemis | 10/9/2026 | 16/9/2026 | An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are… | |
| Analizada | Media (6.5) | 0.70% | — | Apache Artemis | 10/9/2026 | 16/9/2026 | When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The… | |
| Analizada | Crítica (9.1) | 0.57% | — | Apache Artemis | 10/9/2026 | 16/9/2026 | An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to… | |
| Analizada | Alta (7.5) | 0.80% | — | Apache Artemis | 10/9/2026 | 16/9/2026 | An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to… | |
| Analizada | Alta (7.5) | 0.82% | — | Apache Artemis | 10/9/2026 | 16/9/2026 | An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to… | |
| Analizada | Media (6.5) | 0.65% | — | Apache Artemis | 10/9/2026 | 18/9/2026 | An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ… | |
| Pendiente de análisis | Alta (8.8) | 0.85% | — | Apache ArtemisAI | 7/9/2026 | 25/9/2026 | EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the… | |
| Aplazada | Alta (8.9) | 3.6% | — | Shenzhen Aitemi M300 Wi-fi RepeaterAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may… | |
| Analizada | Alta (8.7) | 3.6% | — | Systeminformation | 17/7/2026 | 29/7/2026 | systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian/Ubuntu interfaces(5) source directive because lib/network.js checkLinuxDCHPInterfaces() reads /etc/network/interfaces, extracts a source <path>… | |
| Aplazada | Crítica (9.3) | 2.9% | 💥 PoC | Shenzhen Aitemi M300 Wi-fi RepeaterAI | 1/7/2026 | 6/7/2026 | Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos web backend. Attackers can append… | |
| Modificada | Media (4.3) | 0.56% | — | Apache Artemis | 28/5/2026 | 17/6/2026 | A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular… | |
| Aplazada | Alta (7.8) | 1.2% | — | SysteminformationAI | 27/5/2026 | 28/8/2026 | systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real… | |
| Aplazada | Alta (8) | 0.17% | — | Sitemio Information Technologies Trade WisecpAI | 20/5/2026 | 24/7/2026 | Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This issue affects WISECP: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Pendiente de análisis | Media (5.3) | 0.50% | — | Apache ArtemisAIKnime Business HUBAI | 24/3/2026 | 17/6/2026 | Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exchanged via the broker and injection of new message ( CVE-2026-27446 https://www.cve.org/CVERecord ). Since KNIME Business Hub uses Apache Artemis it is also affected by the issue. However, since… | |
| Analizada | Baja (2.3) | 0.56% | — | Apache Artemis | 24/3/2026 | 17/6/2026 | Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the "createDurableQueue" permission but does… | |
| Analizada | Media (4.6) | 0.25% | — | Broadcom Symantec Siteminder | 10/3/2026 | 17/6/2026 | Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page. | |
| Modificada | Crítica (9.3) | 1.2% | — | Apache Artemis | 4/3/2026 | 18/9/2026 | Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially… | |
| Modificada | Alta (8.8) | 1.3% | — | Systeminformation | 19/2/2026 | 15/7/2026 | systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue. | |
| Modificada | Alta (7.8) | 1.5% | — | Systeminformation | 19/2/2026 | 15/7/2026 | systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an attacker to execute arbitrary OS commands via an unsanitized network interface parameter in the retry code path. In `lib/wifi.js`, the… | |
| Aplazada | Alta (8.3) | 0.27% | — | Saastech Cleaning AND Internet Services INC TemizlikyoldaAI | 11/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikYolda allows Cross-Site Scripting (XSS). This issue affects TemizlikYolda: through 11022026. NOTE: The vendor was contacted early about this disclosure but… | |
| Aplazada | Media (5.4) | 0.21% | — | Saastech Cleaning AND Internet Services INC TemizlikyoldaAI | 11/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikYolda allows Manipulating User-Controlled Variables. This issue affects TemizlikYolda: through 11022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Analizada | Alta (8.1) | 13% | — | Systeminformation | 16/12/2025 | 30/9/2026 | systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing… | |
| Aplazada | Alta (7.5) | 0.32% | — | Starcharge Artemis AC ChargerAI | 27/10/2025 | 17/6/2026 | StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to forge or decrypt valid login tokens. |