Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
3880 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.62% | — | Apache SyncopeAI | 14/9/2026 | 14/9/2026 | Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from… | |
| Aplazada | Media (4.9) | 0.39% | — | Apache SyncopeAI | 14/9/2026 | 14/9/2026 | Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access such sensitive values. This issue affects Apache Syncope: from 3.0.0-M0… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Apache SyncopeAI | 14/9/2026 | 14/9/2026 | Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another Realm and thus be able to effectively duplicate such Connector instance into the Realm… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Apache SyncopeAI | 14/9/2026 | 14/9/2026 | Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such transformation is the Realms filter, which ensures that the search results are matching… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Apache SyncopeAI | 14/9/2026 | 14/9/2026 | Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through… | |
| Aplazada | Alta (7.5) | 0.43% | — | Apache SyncopeAI | 14/9/2026 | 14/9/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body. These values can be then used to perform further REST requests, impersonating users… | |
| Aplazada | Crítica (9.1) | 0.28% | — | Apache SyncopeAI | 14/9/2026 | 14/9/2026 | Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA. This issue affects Apache Syncope:… | |
| Aplazada | Crítica (9.1) | 0.55% | — | Apache SyncopeAI | 14/9/2026 | 14/9/2026 | Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after completing a successful authentication and obtaining a valid JWT. This issue affects… | |
| Aplazada | Alta (7.5) | 0.43% | — | Apache SyncopeAI | 14/9/2026 | 14/9/2026 | Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters. The resulting key value is logged. This issue affects Apache Syncope: from 3.0.15 through 3.0.16, from… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Apache SyncopeAINeo4jAI | 14/9/2026 | 14/9/2026 | Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Apache SyncopeAI | 14/9/2026 | 14/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort clauses for Task search. This issue affects Apache Syncope: from… | |
| Aplazada | Alta (8.8) | 0.47% | — | Apache DorisAI | 14/9/2026 | 14/9/2026 | Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 through 4.0.7, and from 4.1.0 through 4.1.3. Users are recommended to upgrade to a… | |
| Aplazada | Media (6.5) | 0.38% | — | Apache DorisAI | 14/9/2026 | 14/9/2026 | Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information. This issue affects Apache Doris: from 2.0.0 through 2.1.*, from 3.0.0 through 3.0.*, from 4.0.0 before… | |
| Analizada | Crítica (10) | 0.77% | — | Apache Opennlp | 11/9/2026 | 16/9/2026 | The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifiers. An application that obtains these finders through RegexNameFinderFactory.getDefaultRegexNameFinders(...) and then… | |
| Analizada | Alta (7.5) | 0.74% | — | Apache Opennlp | 11/9/2026 | 16/9/2026 | OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. Releases 1.x and 2.x do not contain the affected code.) Description: The SymSpellModelSerializer.create() method reads two… | |
| Pendiente de análisis | Alta (8.5) | 1.0% | — | RenovateAIApache MavenAI | 10/9/2026 | 29/9/2026 | Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve… | |
| Analizada | Alta (8.1) | 0.50% | — | Apache Camel | 10/9/2026 | 14/9/2026 | Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components. This issue affects… | |
| Analizada | Crítica (9.8) | 0.84% | — | Apache Camel | 10/9/2026 | 14/9/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator. This… | |
| Analizada | Crítica (9.8) | 1.0% | — | Apache Camel | 10/9/2026 | 14/9/2026 | Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially… | |
| Analizada | Crítica (9.1) | 0.85% | — | Apache Freemarker | 10/9/2026 | 11/9/2026 | Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled). This issue affects Apache FreeMarker from 2.2.0 through 2.3.34. Users… | |
| Analizada | Crítica (9.1) | 0.86% | — | Apache Artemis | 10/9/2026 | 16/9/2026 | A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0… | |
| Analizada | Crítica (9.8) | 1.1% | 💥 PoC | Apache Artemis | 10/9/2026 | 16/9/2026 | An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are… | |
| Analizada | Media (6.5) | 0.70% | — | Apache Artemis | 10/9/2026 | 16/9/2026 | When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The… | |
| Analizada | Crítica (9.1) | 0.57% | — | Apache Artemis | 10/9/2026 | 16/9/2026 | An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to… | |
| Analizada | Alta (7.5) | 0.80% | — | Apache Artemis | 10/9/2026 | 16/9/2026 | An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to… |