Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
942 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.57% | — | Msgpack-javaAI | 12/9/2026 | 23/9/2026 | msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing… | |
| Analizada | Media (6.1) | 0.46% | — | Mongodb Java Driver | 10/9/2026 | 16/9/2026 | Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an… | |
| Analizada | Alta (8.2) | 0.26% | — | Mongodb Java Driver | 10/9/2026 | 16/9/2026 | A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled may cause the hosting application… | |
| Pendiente de análisis | Alta (8.8) | 0.54% | — | Amazon Deep Java LibraryAI | 10/9/2026 | 10/9/2026 | An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue,… | |
| Aplazada | Crítica (9.2) | 0.34% | — | Eclipse Ditto Javascript Client NodeAIEclipse Ditto Javascript Client Node 1AI | 8/9/2026 | 9/9/2026 | In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the… | |
| Pendiente de análisis | Crítica (9) | 0.61% | — | SAP GUI FOR JavaAI | 8/9/2026 | 9/9/2026 | SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the… | |
| Aplazada | Media (5.5) | 0.70% | — | Java-json-tools Jackson-coreutilsAI | 8/9/2026 | 28/9/2026 | A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the component JSON Pointer parser. The manipulation results in allocation of resources. The… | |
| Aplazada | Media (5.5) | 0.70% | — | Java-json-tools Jackson-coreutilsAI | 8/9/2026 | 28/9/2026 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation results in resource consumption. The attack may be initiated remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.66% | — | Java-json-tools Jackson-coreutilsAI | 7/9/2026 | 8/9/2026 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack… | |
| Aplazada | Media (5.5) | 0.70% | — | Java-json-tools Json PatchAI | 7/9/2026 | 9/9/2026 | A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Handler. The manipulation leads to resource consumption. It is possible to initiate… | |
| Pendiente de análisis | Alta (8.7) | 0.58% | — | Amazon Ion-javaAI | 4/9/2026 | 8/9/2026 | Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insufficient coverage of the GZIP auto-decompression opt-out introduced for… | |
| Pendiente de análisis | Alta (8.7) | 0.62% | — | Nginx JavascriptAI | 2/9/2026 | 2/9/2026 | A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the fetched HTTP response. Impact: This vulnerability may allow remote attackers to cause a… | |
| Pendiente de análisis | Media (6.5) | 0.37% | — | Oracle Java SEAI | 26/8/2026 | 28/8/2026 | Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized… | |
| Pendiente de análisis | Crítica (9.1) | 0.23% | — | Drupal Photoswipe - Responsive Javascript Modal Image GalleryAI | 25/8/2026 | 28/8/2026 | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0. | |
| Aplazada | Alta (7.5) | 0.69% | — | Jknack Handlebars.javaAIJknack Handlebars-springmvcAI | 20/8/2026 | 18/9/2026 | Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the path-containment validation used by other URL-based loaders. In… | |
| Aplazada | Media (5.7) | 0.24% | — | Eclipse Openjava9AI | 19/8/2026 | 1/9/2026 | In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a segmentation fault. | |
| Pendiente de análisis | Media (5.3) | 0.28% | — | Oracle Java SEAIOracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAI | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Oracle Java SEAI | 18/8/2026 | 22/8/2026 | Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in… | |
| Pendiente de análisis | Media (6.8) | 0.31% | — | Oracle Java SEAIOracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAI | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM… | |
| Pendiente de análisis | Baja (3.7) | 0.27% | — | Oracle Java SEAIOracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAI | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM… | |
| Pendiente de análisis | Alta (8.7) | 0.61% | — | Amazon Ion-javaAI | 18/8/2026 | 20/8/2026 | Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression. To remediate this issue, users should upgrade to… | |
| Pendiente de análisis | Alta (8.7) | 0.61% | — | Amazon Ion-javaAI | 18/8/2026 | 20/8/2026 | Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap preallocation. To remediate this issue, users should upgrade to version… | |
| Pendiente de análisis | Alta (8.7) | 0.73% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F… | |
| Pendiente de análisis | Media (5.1) | 0.31% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) configure com.rabbitmq.client.TrustEverythingTrustManager and leave hostname… | |
| Pendiente de análisis | Media (6.3) | 0.52% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header whose remainingBodyBytes value is smaller… |