Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.3% | — | Redhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+4 | 2/9/2025 | 6/10/2026 | A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol… | |
| Aplazada | Media (5.5) | 0.37% | — | Zlt2000 Microservices-platformAIVmware Spring BootAI | 8/8/2025 | 17/6/2026 | A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /actuator of the component Spring Actuator Interface. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Media (5.3) | 0.34% | — | ZipkinAIVmware Spring Boot ActuatorAI | 4/7/2025 | 17/6/2026 | Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927. | |
| Aplazada | Baja (2.1) | 0.51% | — | Hansonwang99 Spring-boot-in-actionAI | 16/6/2025 | 17/6/2026 | A vulnerability was found in hansonwang99 Spring-Boot-In-Action up to 807fd37643aa774b94fd004cc3adbd29ca17e9aa. It has been declared as critical. Affected by this vulnerability is the function watermarkTest of the file /springbt_watermark/src/main/java/cn/codesheep/springbt_watermark/service/ImageUploadService.java of… | |
| Aplazada | Alta (7.7) | 4.0% | — | JavaAIVmware Spring BootAI | 21/5/2025 | 17/6/2026 | OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized access to sensitive… | |
| Aplazada | Media (5.3) | 0.57% | — | Vector4wang Spring-boot-quickAI | 10/5/2025 | 17/6/2026 | A vulnerability was found in vector4wang spring-boot-quick up to 20250422. It has been rated as critical. This issue affects the function ResponseEntity of the file /spring-boot-quick-master/quick-img2txt/src/main/java/com/quick/controller/Img2TxtController.java of the component quick-img2txt. The manipulation leads… | |
| Aplazada | Media (5.3) | 0.57% | — | Alanbinu007 Spring-boot-advanced-projectsAI | 1/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in AlanBinu007 Spring-Boot-Advanced-Projects up to 3.1.3. This affects the function uploadUserProfileImage of the file /Spring-Boot-Advanced-Projects-main/Project-4.SpringBoot-AWS-S3/backend/src/main/java/com/urunov/profile/UserProfileController.java of the… | |
| Aplazada | Alta (8.7) | 3.4% | — | Vmware Spring BootAI | 14/11/2024 | 17/6/2026 | common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or… | |
| Aplazada | Media (6.3) | 0.12% | — | Vmware Spring Boot LoaderAIVmware Spring Boot Loader ClassicAI | 23/8/2024 | 17/6/2026 | Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another. | |
| Modificada | Alta (7.5) | 2.6% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Build OF KeycloakRedhat Data Grid+5 | 21/8/2024 | 24/9/2026 | A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder… | |
| Modificada | Alta (7.5) | 0.45% | — | Talelin Lin-cms-spring-boot | 19/7/2024 | 17/6/2026 | Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component. | |
| Aplazada | Alta (8.8) | 1.0% | — | Lsgwr Spring Boot Online ExamAI | 30/4/2024 | 17/6/2026 | Directory Traversal vulnerability in lsgwr spring boot online exam v.0.9 allows an attacker to execute arbitrary code via the FileTransUtil.java component. | |
| Modificada | Alta (7.5) | 4.6% | — | Netapp Active IQ Unified ManagerNetapp Oncommand Workflow AutomationRedhat FuseRedhat Integration Camel FOR Spring Boot+5 | 19/2/2024 | 2/10/2026 | A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits… | |
| Modificada | Media (6.5) | 1.2% | — | Vmware Spring Boot | 28/11/2023 | 17/6/2026 | In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.5) | 0.97% | — | Codecentric Spring Boot AdminThymeleaf | 14/7/2023 | 17/6/2026 | Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to… | |
| Modificada | Alta (7.5) | 0.91% | — | Vmware Spring Boot | 26/5/2023 | 17/6/2026 | In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache. | |
| Modificada | Media (5.3) | 0.75% | — | Spring-boot-actuator-logview Project Spring-boot-actuator-logview | 11/5/2023 | 17/6/2026 | spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view. | |
| Modificada | Crítica (9.8) | 1.1% | — | Vmware Spring Boot | 20/4/2023 | 17/6/2026 | In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to… | |
| Modificada | Alta (7.5) | 0.60% | — | Redhat Build OF QuarkusRedhat Integration Camel FOR Spring BootRedhat Integration Camel KRedhat Integration Service Registry+6 | 23/2/2023 | 17/6/2026 | The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol. | |
| Modificada | Alta (7.5) | 1.6% | — | Apache ShiroVmware Spring Boot | 14/1/2023 | 17/6/2026 | When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro and Spring Boot < 2.6 default to Ant style pattern matching.… | |
| Modificada | Crítica (9.8) | 1.5% | — | Codecentric Spring Boot Admin | 9/12/2022 | 17/6/2026 | Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent… | |
| Modificada | Crítica (9.8) | 2.6% | — | Vmware Bosh EditorVmware Cloudfoundry Manifest YML SupportVmware Concourse CI Pipeline EditorVmware Spring Boot Tools+1 | 4/11/2022 | 17/6/2026 | Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the… | |
| Modificada | Alta (7.5) | 5.0% | — | Talelin Lin-cms-spring-boot | 21/7/2022 | 17/6/2026 | An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application. | |
| Modificada | Alta (7.8) | 0.60% | — | Vmware Spring Boot | 30/3/2022 | 17/6/2026 | spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerability only affects products and/or versions that are no longer… |