Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.61% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not… | |
| Analizada | Alta (7.3) | 0.78% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module… | |
| Analizada | Media (6.5) | 0.39% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with no prior access to the secret — could read a team-scoped… | |
| Modificada | Media (6.5) | 0.23% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that… | |
| Analizada | Media (5.4) | 0.53% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary `airflow.*` classes on… | |
| Modificada | Alta (8.8) | 0.48% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author… | |
| Analizada | Media (4.3) | 0.42% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nested value was shown unmasked in the… | |
| Analizada | Media (6.5) | 0.60% | — | Apache-airflow-providers-google | 12/8/2026 | 16/9/2026 | The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a… | |
| Analizada | Crítica (9.1) | 0.33% | — | Apache Httpclient | 11/8/2026 | 24/9/2026 | Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by… | |
| Analizada | Crítica (9.1) | 0.78% | — | Apache Allura | 11/8/2026 | 17/8/2026 | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. | |
| Aplazada | Media (5.3) | 0.44% | — | Cti-transmuteAIApache EchartsAI | 11/8/2026 | 26/8/2026 | Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names may originate directly from STIX or MISP data, including STIX types, relationship_type, pattern prefixes, and MISP category/type values. Since ECharts interprets the… | |
| Analizada | Media (6.5) | 0.60% | — | Apache-airflow-providers-amazon | 10/8/2026 | 16/9/2026 | The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve… | |
| Analizada | Media (6.5) | 0.36% | — | Apache-airflow-providers-apache-yandex | 10/8/2026 | 16/9/2026 | The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team… | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | Apache AirflowAIApache Airflow-providers-microsoft-azureAI | 10/8/2026 | 16/9/2026 | The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to… | |
| Aplazada | Crítica (9.3) | 0.47% | — | MetacatAIApache TomcatAI | 10/8/2026 | 9/9/2026 | Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endpoint that is part of the original 1.x Metacat API.… | |
| Analizada | Alta (7.3) | 0.62% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a recommended option for production deployments. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Media (6.5) | 0.64% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Alta (7.5) | 0.59% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Alta (7.5) | 0.71% | — | Apache Tapestry | 10/8/2026 | 18/8/2026 | Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue. | |
| Analizada | Alta (7.5) | 0.66% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Crítica (9.8) | 1.2% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Crítica (9.8) | 1.2% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Crítica (9.8) | 1.3% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Crítica (9.8) | 0.73% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | |
| Analizada | Crítica (9.8) | 0.69% | — | Apache Ranger | 10/8/2026 | 17/8/2026 | SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue. |