Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
930 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.3) | 0.38% | — | Broadcom Vmware AVI Load Balancer | 18/7/2026 | 20/8/2026 | VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7)… | |
| Analizada | Crítica (9.8) | 0.61% | — | Broadcom Vmware AVI Load Balancer | 18/7/2026 | 20/8/2026 | VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through… | |
| Pendiente de análisis | Media (5.1) | 0.17% | — | Microsoft WindowsAIMicrosoft Task SchedulerAIMicrosoft DcomAI | 17/7/2026 | 21/7/2026 | A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3) | |
| Analizada | Crítica (9.6) | 0.48% | — | Broadcom Spring Authorization Server | 16/7/2026 | 4/9/2026 | Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10. | |
| Analizada | Media (5.3) | 0.41% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read… | |
| Analizada | Alta (7.5) | 0.55% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths and consume broker… | |
| Analizada | Alta (8.7) | 2.8% | — | Broadcom Rabbitmq Server | 10/7/2026 | 29/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and… | |
| Analizada | Media (4.9) | 0.35% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user… | |
| Analizada | Alta (7) | 0.35% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow.… | |
| Analizada | Crítica (10) | 0.50% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is… | |
| Analizada | Alta (7) | 0.38% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed deletion checks, leaving persistent route… | |
| Analizada | Alta (7.1) | 0.22% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript… | |
| Modificada | Media (5.7) | 0.25% | — | Broadcom Rabbitmq Server | 10/7/2026 | 14/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser… | |
| Analizada | Alta (7.1) | 0.43% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This… | |
| Analizada | Crítica (10) | 0.63% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound… | |
| Analizada | Alta (8.8) | 0.76% | — | Broadcom Spring Statemachine | 23/6/2026 | 22/9/2026 | Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring… | |
| Analizada | Alta (7.5) | 0.46% | — | Broadcom Spring Cloud Sleuth | 15/6/2026 | 17/6/2026 | In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled.… | |
| Analizada | Baja (3.7) | 0.26% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when… | |
| Analizada | Alta (8.6) | 0.43% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to. Affected versions: Spring… | |
| Analizada | Alta (8.2) | 0.39% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could… | |
| En análisis | Media (5.3) | 0.46% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote attackers in… | |
| Analizada | Media (4.8) | 0.15% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key material unless operators explicitly reconfigured the flag. Affected versions:… | |
| Analizada | Media (5.4) | 0.18% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts). Affected versions: Spring Web Services 5.0.0… | |
| Analizada | Alta (8.2) | 0.34% | — | Broadcom Spring WEB Services | 11/6/2026 | 4/9/2026 | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks. Affected… | |
| Analizada | Media (4.8) | 0.25% | — | Broadcom Spring WEB Flow | 11/6/2026 | 4/9/2026 | Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker. Affected versions:… |