Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
3880 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.82% | — | Apache Artemis | 10/9/2026 | 16/9/2026 | An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to… | |
| Analizada | Media (6.5) | 0.65% | — | Apache Artemis | 10/9/2026 | 18/9/2026 | An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ… | |
| Analizada | Alta (8.1) | 0.36% | — | Apache Parquet | 9/9/2026 | 10/9/2026 | Potential problem for users of the org.apache.parquet.crypto.keytools package in Apache Parquet, versions 1.12 to 1.18. This package enables users to encrypt Parquet files via an envelope encryption mechanism that wraps (encrypts) data keys via a Key Management Service (KMS). On the reader side, the KMS URL can be… | |
| Analizada | Alta (8.1) | 0.54% | — | Apache Impala | 9/9/2026 | 10/9/2026 | Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue. | |
| Analizada | Alta (8.8) | 0.58% | — | Apache Impala | 9/9/2026 | 10/9/2026 | Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the `hadoop.security.credential.provider.path` property of `core-site.xml`. The… | |
| Analizada | Crítica (9.8) | 0.46% | — | Apache Impala | 9/9/2026 | 10/9/2026 | Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue. | |
| Analizada | Media (5.3) | 0.54% | — | Apache Impala | 9/9/2026 | 10/9/2026 | Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users… | |
| Analizada | Crítica (9.8) | 0.74% | — | Apache Nutch | 9/9/2026 | 10/9/2026 | Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is… | |
| Analizada | Alta (8.8) | 0.66% | — | Apache Nutch | 9/9/2026 | 11/9/2026 | Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.11… | |
| Analizada | Crítica (9.1) | 0.72% | — | Apache Nutch | 9/9/2026 | 10/9/2026 | Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is not possible, user must restrict… | |
| Analizada | Alta (7.5) | 0.62% | — | Apache ActivemqApache Activemq ALLApache Activemq Broker | 9/9/2026 | 18/9/2026 | Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All:… | |
| Analizada | Crítica (9.1) | 0.38% | — | Apache-airflow-providers-fab | 8/9/2026 | 18/9/2026 | Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's **multi-tenant**… | |
| Pendiente de análisis | Alta (8.8) | 0.85% | — | Apache ArtemisAI | 7/9/2026 | 25/9/2026 | EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the… | |
| Analizada | Alta (7.4) | 0.52% | — | Apache ANT | 7/9/2026 | 9/9/2026 | The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in… | |
| Aplazada | Crítica (9.4) | 2.9% | — | Tenda CP3AIApache KylinAI | 5/9/2026 | 8/9/2026 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely. | |
| Pendiente de análisis | Alta (8.5) | 1.1% | — | Apache Log4jAIAmazon LinuxAI | 4/9/2026 | 8/9/2026 | An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters. | |
| Aplazada | Alta (8.8) | 0.46% | — | Apache GriffinAI | 4/9/2026 | 8/9/2026 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module. This issue affects Apache Griffin Hive Metastore Module: all versions. As this project is retired, we do not plan to release a version that fixes… | |
| Aplazada | Media (6.1) | 0.25% | — | Apache SkywalkingAI | 4/9/2026 | 8/9/2026 | ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0. Users are recommended to upgrade to Horizon UI 1.0.0, which fixes the issue. | |
| Aplazada | Media (6.1) | 0.26% | — | Apache AlluraAI | 4/9/2026 | 8/9/2026 | Apache Allura: stored XSS via SVN code repositories. Git repositories are not known to be affected. The vulnerability is likely mitigated via default CSP headers. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue. | |
| Aplazada | Alta (7.5) | 0.43% | — | Apache AlluraAI | 4/9/2026 | 8/9/2026 | Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue. | |
| Aplazada | Crítica (9.1) | 0.46% | — | Apache AlluraAI | 4/9/2026 | 8/9/2026 | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue. | |
| Aplazada | Media (6.1) | 0.26% | — | Apache AlluraAI | 4/9/2026 | 8/9/2026 | Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue. | |
| Aplazada | Media (5.3) | 0.22% | — | Apache SkywalkingAI | 4/9/2026 | 8/9/2026 | PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. PagerDuty serves this endpoint over HTTPS and will normally answer plain HTTP with a redirect. That does not remove the exposure. The initial POST -- including the JSON body containing the routing key -- is written to the socket… | |
| Aplazada | Crítica (9.5) | 0.34% | — | Eclipse ArrowheadAIApache TomcatAI | 3/9/2026 | 3/9/2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate that the client sends inside the MQTT message payload (the authentication field of MqttRequestTemplate) and treats its Subject DN as the… | |
| Aplazada | Alta (8.9) | 0.47% | — | Eclipse ArrowheadAIApache TomcatAIVmware Spring MVCAIVmware Spring SecurityAI | 3/9/2026 | 3/9/2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on… |