Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

359 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.3%—Eclipse Threadx Usbx24/5/202217/6/2026
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. Prior to version 6.1.11, he USBX DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memory contents. In particular cases this may allow an attacker to bypass security features or execute arbitrary…
ModificadaCrítica (9.8)1.2%—Eclipse Threadx Usbx24/5/202217/6/2026
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. In versions prior to 6.1.10, an attacker can cause a buffer overflow by providing the Azure RTOS USBX host stack a HUB descriptor with `bNbPorts` set to a value greater than `UX_MAX_TT` which defaults to 8. For a `bNbPorts` value of 255, the…
ModificadaCrítica (9.8)2.1%—Eclipse Cyclonedds5/5/202217/6/2026
Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.
ModificadaCrítica (9.8)2.1%—Eclipse Cyclonedds5/5/202217/6/2026
Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser.
ModificadaMedia (5.3)1.1%—Eclipse Openj9Oracle Java SE27/4/202217/6/2026
In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.
ModificadaMedia (6.5)1.0%—Eclipse Lemminx18/2/202217/6/2026
A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal.
ModificadaMedia (5.5)0.30%—Eclipse Lemminx18/2/202217/6/2026
A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive information locally if LemMinX is run under a privileged user.
ModificadaAlta (7.5)1.4%—Eclipse Wakaama1/2/202217/6/2026
In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.
ModificadaAlta (7.5)1.4%—Eclipse Mosquitto1/12/202117/6/2026
In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and possible denial of service.
ModificadaMedia (6.1)0.74%—Eclipse Theia10/11/202117/6/2026
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
ModificadaCrítica (9.8)1.2%—Eclipse Paho Mqtt C/c++ Client3/11/202117/6/2026
In versions prior to 1.1 of the Eclipse Paho MQTT C Client, the client does not check rem_len size in readpacket.
ModificadaCrítica (9.8)1.8%—Eclipse Openj925/10/202117/6/2026
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
ModificadaAlta (8.1)0.41%—Eclipse CHE29/9/202117/6/2026
The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacement of the original binaries with arbitrary ones. The stacks involved are Java 8 (alpine and…
ModificadaAlta (8.1)1.1%—Eclipse Equinox13/9/202117/6/2026
In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middle attack if using p2 repos that are HTTP; that can then be exploited to serve incorrect p2 metadata and entirely alter the local installation, particularly by installing plug-ins…
ModificadaCrítica (9.9)4.6%—Eclipse Keti9/9/202117/6/2026
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a sandbox escape vulnerability may lead to post-authentication Remote Code execution. This vulnerability is known to exist in the latest commit at the time of writing this CVE (commit a1c8dbe). For…
ModificadaCrítica (9.9)0.95%—Eclipse Keti9/9/202117/6/2026
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which will escape the configured Groovy sandbox. This vulnerability is known to exist in the latest…
ModificadaCrítica (9.8)2.2%—Eclipse Theia2/9/202117/6/2026
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.
ModificadaAlta (8.8)0.60%—Eclipse Theia1/9/202117/6/2026
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file..
ModificadaMedia (5.3)1.3%—Eclipse MosquittoFedoraproject Fedora30/8/202117/6/2026
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.
ModificadaAlta (7.5)1.9%—Eclipse Cyclone Data Distribution Service23/8/202117/6/2026
A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
ModificadaAlta (7.5)1.9%—Eclipse Cyclone Data Distribution Service23/8/202117/6/2026
A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
ModificadaAlta (7.5)0.34%—Eclipse Californium20/8/202117/6/2026
In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's ServerKeyExchange.
ModificadaAlta (7.5)1.2%—Eclipse Mosquitto27/7/20212/7/2026
In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.
ModificadaMedia (6.5)1.1%—Eclipse Mosquitto22/7/202117/6/2026
In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker.
ModificadaMedia (5.3)99%💥 ExploitEclipse JettyNetapp E-series Santricity OS ControllerNetapp E-series Santricity WEB ServicesNetapp Element Plug-in FOR Vcenter Server+1415/7/202117/6/2026
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.
Orbitaley — Vulnerabilidades