Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
3883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 2.6% | 💥 PoC | Apache Ranger | 10/8/2026 | 17/8/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8. | |
| Pendiente de análisis | Alta (7.5) | 0.59% | — | Apache IotdbAI | 10/8/2026 | 12/8/2026 | Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sending a crafted malformed Thrift frame, an attacker can cause IoTDB to allocate an excessive amount of memory and crash with an OutOfMemoryError. This issue affects Apache… | |
| Analizada | Crítica (9.1) | 0.77% | — | Apache Fory | 7/8/2026 | 8/8/2026 | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially… | |
| Analizada | Alta (7.5) | 0.80% | — | Apache Fory | 7/8/2026 | 8/8/2026 | Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0. Users of other language… | |
| Analizada | Crítica (9.8) | 0.99% | — | Apache Fory | 7/8/2026 | 8/8/2026 | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the… | |
| Analizada | Alta (7.5) | 0.51% | — | Apache Apr-util | 6/8/2026 | 7/8/2026 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3. | |
| Analizada | Alta (7.5) | 0.51% | — | Apache Apr-util | 6/8/2026 | 7/8/2026 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue. | |
| Analizada | Crítica (9.1) | 0.59% | — | Apache Apr-util | 6/8/2026 | 7/8/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3 | |
| Analizada | Crítica (9.1) | 0.46% | — | Apache Apr-util | 6/8/2026 | 7/8/2026 | A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | |
| Analizada | Alta (7.5) | 0.38% | — | Apache Apr-util | 6/8/2026 | 29/9/2026 | APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to… | |
| Modificada | Alta (7.5) | 0.66% | — | Apache CXF | 6/8/2026 | 7/8/2026 | In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked… | |
| Modificada | Crítica (9.8) | 0.68% | — | Apache CXF | 6/8/2026 | 7/8/2026 | In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended… | |
| Modificada | Crítica (9.1) | 0.28% | — | Apache CXF | 6/8/2026 | 7/8/2026 | Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator.… | |
| Modificada | Crítica (9.1) | 0.28% | — | Apache CXF | 6/8/2026 | 7/8/2026 | Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge,… | |
| Modificada | Crítica (9.1) | 0.71% | — | Apache CXF | 6/8/2026 | 7/8/2026 | In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time.… | |
| Modificada | Alta (8.1) | 0.47% | — | Apache CXF | 6/8/2026 | 7/8/2026 | A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue. | |
| Modificada | Crítica (9.8) | 1.1% | — | Apache CXF | 6/8/2026 | 7/8/2026 | Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget… | |
| Modificada | Alta (7.5) | 0.65% | — | Apache CXF | 6/8/2026 | 7/8/2026 | Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declarations or external entities. As a result, the protections… | |
| Analizada | Alta (7.5) | 0.66% | — | Apache CXF | 6/8/2026 | 6/8/2026 | An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. | |
| Modificada | Alta (7.5) | 0.73% | — | Apache CXF | 6/8/2026 | 7/8/2026 | Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which may lead to denial of service attacks when processing requests with very large numbers of form parameters. Users are recommended to upgrade… | |
| Modificada | Alta (8.1) | 0.69% | — | Apache CXF | 6/8/2026 | 7/8/2026 | The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code… | |
| Modificada | Alta (7.5) | 0.73% | — | Apache CXF | 6/8/2026 | 7/8/2026 | Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit. Users should update to Apache CXF 4.2.3 or… | |
| Modificada | Media (5.3) | 0.49% | 💥 PoC | Apache Polaris | 6/8/2026 | 6/8/2026 | Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's storage credentials to read a… | |
| Analizada | Crítica (9.1) | 0.57% | — | Apache Answer | 5/8/2026 | 7/8/2026 | Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly… | |
| Analizada | Alta (7.5) | 0.62% | — | Apache Answer | 5/8/2026 | 6/8/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be retrieved by unauthorized users through the single-answer read path when the parent question remained visible, exposing answer content that… |