Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Baja (1.1) | 0.14% | — | Paloaltonetworks Cortex XDR Broker VM | 9/7/2026 | 16/7/2026 | A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user. | |
| Analizada | Alta (7.5) | 0.56% | — | Apache ActivemqApache Activemq Broker | 30/6/2026 | 2/7/2026 | Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only checked in the client, allowing a different connection to… | |
| Analizada | Alta (7.5) | 0.74% | — | Apache ActivemqApache Activemq Broker | 30/6/2026 | 2/7/2026 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker. An authenticated user can cause a broker DoS by sending a crafted OpenWire Message with a large encoded size value for the map. OpenWire message property maps are… | |
| Analizada | Alta (7.5) | 0.69% | — | Apache ActivemqApache Activemq Broker | 30/6/2026 | 2/7/2026 | Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without sending a ConnectionInfo, until the broker will crash with OOM.… | |
| Analizada | Alta (7.5) | 0.63% | — | Apache ActivemqApache Activemq Broker | 30/6/2026 | 2/7/2026 | Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker… | |
| Analizada | Media (5.9) | 0.51% | — | Apache ActivemqApache Activemq Broker | 1/6/2026 | 22/7/2026 | Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic… | |
| Analizada | Media (4.3) | 0.50% | — | Apache ActivemqApache Activemq Broker | 1/6/2026 | 22/7/2026 | Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6;… | |
| Analizada | Alta (8.8) | 0.88% | — | Apache ActivemqApache Activemq Broker | 1/6/2026 | 21/7/2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as `masterslave:vm://...,...` and `static:vm://...` incorrectly pass validation allowing bypass of fix in… | |
| Analizada | Alta (8.1) | 0.66% | 💥 PoC | Apache ActivemqApache Activemq Broker | 1/6/2026 | 22/7/2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations… | |
| Analizada | Baja (1.1) | 0.10% | — | Paloaltonetworks Broker VM | 13/5/2026 | 13/7/2026 | A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields. | |
| Modificada | Alta (8.8) | 1.1% | 💥 PoC | Apache ActivemqApache Activemq Broker | 24/4/2026 | 15/7/2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. An authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validation to include an xbean binding… | |
| Modificada | Alta (8.8) | 4.1% | 💥 Exploit | Apache ActivemqApache Activemq Broker | 24/4/2026 | 15/7/2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerView.addNetworkConnector… | |
| Modificada | Alta (7.5) | 1.1% | — | Apache ActivemqApache Activemq Broker | 10/4/2026 | 15/7/2026 | Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust… | |
| Analizada | Alta (8.8) | 15% | ⚠ Explotación activa💥 Exploit | Apache ActivemqApache Activemq Broker | 7/4/2026 | 4/8/2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ… | |
| Analizada | Media (4.3) | 0.68% | — | Apache ActivemqApache Activemq BrokerApache Activemq WEB | 7/4/2026 | 17/6/2026 | Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key"… | |
| Aplazada | Alta (8.1) | 0.37% | — | Optimus Brokerage AutomationAI | 14/11/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Client, Authentication Bypass, Manipulate Registry Information. This issue affects… | |
| Aplazada | Media (6.4) | 0.21% | — | Redhat AMQ BrokerAI | 22/10/2025 | 17/6/2026 | A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their… | |
| Aplazada | Media (4.7) | 0.18% | — | Yosmart Yolink HUBAIYosmart Yolink Mobile ApplicationAIYosmart Yolink Mqtt BrokerAI | 6/10/2025 | 17/6/2026 | Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices. This affects YoLink Hub 0382, YoLink… | |
| Aplazada | Media (5.3) | 0.17% | — | Paloaltonetworks Cortex XDR Broker VMAI | 13/8/2025 | 17/6/2026 | A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the… | |
| Aplazada | Media (4.6) | 0.19% | — | Paloaltonetworks Cortex XDR BrokerAI | 13/6/2025 | 17/6/2026 | An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated administrative user to execute certain files available within the Broker VM and escalate their privileges to root. | |
| Aplazada | Media (6.5) | 0.49% | — | Paloaltonetworks Cortex XDR Broker VMAI | 14/5/2025 | 17/6/2026 | A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM. | |
| Aplazada | Media (6.9) | 0.44% | — | Paloaltonetworks Cortex XDR Broker VMAI | 14/5/2025 | 17/6/2026 | A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM. The attacker must have network access to the Broker VM to exploit this issue. | |
| Aplazada | Media (6.3) | 0.56% | — | Paloaltonetworks Cortex XDR Broker VMAI | 11/4/2025 | 17/6/2026 | A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM. | |
| Aplazada | Media (6.5) | 0.26% | — | Idxbroker ImpressAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IDX Broker IMPress for IDX Broker idx-broker-platinum allows Stored XSS.This issue affects IMPress for IDX Broker: from n/a through <= 3.2.3. | |
| Aplazada | Media (5.3) | 0.26% | — | Paloaltonetworks Cortex XDR Broker VMAI | 12/2/2025 | 17/6/2026 | A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthorized access to Docker containers from the host network used by Broker VM. This may allow access to read files sent for analysis and logs transmitted by the Cortex XDR Agent to the Cortex XDR server. |