Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.5) | 0.35% | — | Google Cloud Integration ConnectorsAI | 4/9/2026 | 8/9/2026 | A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on… | |
| Aplazada | Media (5.4) | 0.14% | — | Simple Membership Mailchimp IntegrationAI | 2/9/2026 | 3/9/2026 | The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration data (name, email, membership level) is… | |
| Analizada | Media (5.3) | 0.33% | — | Miniorange Ldap / Active Directory Integration | 2/9/2026 | 16/9/2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1. | |
| Analizada | Alta (8.2) | 0.28% | — | Vmware Spring Integration | 27/8/2026 | 1/9/2026 | When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message… | |
| Analizada | Media (6.3) | 0.29% | — | Vmware Spring Integration | 27/8/2026 | 1/9/2026 | The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a GenericMessage with MutableMessageHeaders without sanitizing or filtering… | |
| Analizada | Media (5.4) | 0.18% | — | Vmware Spring Integration | 27/8/2026 | 31/8/2026 | A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report THREADING=null (not thread-safe, e.g. the Kotlin kts engine), concurrent message processing can corrupt engine-internal state, potentially leaking one message's payload/headers bindings into another… | |
| Analizada | Media (6.8) | 0.39% | — | Vmware Spring Integration | 27/8/2026 | 31/8/2026 | A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration… | |
| Analizada | Alta (8) | 0.42% | — | Vmware Spring Integration | 27/8/2026 | 31/8/2026 | An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is a Spring-managed bean. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 | |
| Analizada | Media (6.6) | 0.24% | — | Vmware Spring Integration | 27/8/2026 | 31/8/2026 | Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration… | |
| Analizada | Baja (3.2) | 0.15% | — | Vmware Spring Integration | 27/8/2026 | 31/8/2026 | PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/spring-integration/metadata-store.properties with world-readable permissions. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 -… | |
| Analizada | Media (6.5) | 0.42% | — | Vmware Spring Integration | 27/8/2026 | 1/9/2026 | The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring… | |
| Analizada | Media (5.4) | 0.26% | — | Vmware Spring Integration | 27/8/2026 | 10/9/2026 | A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integration MessageHeaders. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5… | |
| Analizada | Crítica (9.8) | 5.9% | — | Vmware Spring Integration | 27/8/2026 | 2/9/2026 | SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to a Serializable type is read directly via readObject(). If an application using this… | |
| Analizada | Media (5.4) | 0.30% | — | Vmware Spring Integration | 27/8/2026 | 2/9/2026 | An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration… | |
| Analizada | Media (6.3) | 0.33% | — | Vmware Spring Integration | 27/8/2026 | 2/9/2026 | An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring… | |
| Analizada | Media (6.5) | 0.29% | — | Vmware Spring Integration | 27/8/2026 | 4/9/2026 | RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of exactly that size with no upper bound. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5… | |
| Analizada | Media (6.3) | 0.31% | — | Vmware Spring Integration | 27/8/2026 | 4/9/2026 | Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring… | |
| Pendiente de análisis | Crítica (9.3) | 0.41% | — | Google Cloud Application IntegrationAI | 22/8/2026 | 31/8/2026 | A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required. | |
| Aplazada | Crítica (9.1) | 0.38% | — | EPA 3.X IntegrationAI | 18/8/2026 | 8/9/2026 | ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU server certificate validation in app/vau/VAUProtokoll.py without anchoring the signed_vau_server_pub_keys and AUT_VAU_CertData… | |
| Aplazada | Alta (7.5) | 0.31% | — | EPA 3.X IntegrationAI | 18/8/2026 | 8/9/2026 | ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration disables TLS certificate verification for both ePA connections in app/vau/VAUProtokoll.py and Konnektor connections in app/konnektor/Konnektor.py.… | |
| Aplazada | Alta (7.4) | 0.51% | — | EPA 3.X IntegrationAI | 18/8/2026 | 8/9/2026 | ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter unchanged in app/vau/VAUProtokoll.py while constructing VAU messages. The frozen client request counter causes the server… | |
| Aplazada | Media (6.8) | 0.49% | — | EPA 3.X IntegrationAI | 18/8/2026 | 8/9/2026 | ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration does not neutralize CRLF characters in values used by app/vau/VAUProtokoll.py to construct VAU inner HTTP requests. The build_inner_header… | |
| Aplazada | Baja (2.1) | 0.40% | — | Codecanyon Timecamp Integration FOR CRMAI | 17/8/2026 | 20/8/2026 | A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/save_contact of the component Contact Information Update. Such manipulation of the argument contact_id leads to authorization bypass. The attack can be launched remotely.… | |
| Pendiente de análisis | Crítica (9.9) | 0.70% | — | Argoproj ArgocdAIOpen Cluster Management Multicloud IntegrationsAI | 12/8/2026 | 27/8/2026 | A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary… | |
| Pendiente de análisis | Crítica (9.6) | 0.52% | — | Argoproj ArgocdAIRedhat Advanced Cluster ManagementAIRedhat Multicloud IntegrationsAI | 12/8/2026 | 27/8/2026 | A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure… |