Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Protonj2 | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Protonj2 | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | |
| Analizada | Alta (8.8) | 0.74% | — | Apache Nifi | 3/8/2026 | 5/8/2026 | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could… | |
| Analizada | Baja (2.3) | 0.48% | — | Apache Nifi | 3/8/2026 | 5/8/2026 | Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized… | |
| Analizada | Media (5.9) | 0.81% | — | Apache Nifi | 3/8/2026 | 5/8/2026 | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and… | |
| Analizada | Alta (7.7) | 0.45% | — | Apache Nifi | 3/8/2026 | 10/8/2026 | Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with… | |
| Analizada | Alta (7.5) | 0.81% | — | Apache Jena Fuseki | 3/8/2026 | 7/8/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. | |
| Modificada | Media (5.3) | 0.46% | — | Apache Httpclient | 31/7/2026 | 13/8/2026 | HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue… | |
| Analizada | Alta (8.1) | 0.79% | — | Apache Kyuubi | 31/7/2026 | 10/8/2026 | The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0. Users are recommended to… | |
| Analizada | Media (6.5) | 0.80% | — | Apache Zeppelin | 31/7/2026 | 10/8/2026 | Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths. Zeppelin composed these values into filesystem paths using the server's… | |
| Analizada | Media (6.9) | 0.75% | — | Apache Tika | 30/7/2026 | 10/8/2026 | Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue. | |
| Analizada | Media (5.9) | 0.63% | — | Apache Tika | 30/7/2026 | 1/9/2026 | Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible to the Tika process and have their contents emitted into… | |
| Analizada | Crítica (9.8) | 1.1% | 💥 PoC | Apache Kyuubi | 30/7/2026 | 5/8/2026 | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled… | |
| Analizada | Media (6.5) | 0.56% | — | Apache Jspwiki | 30/7/2026 | 5/8/2026 | A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This issue affects Apache JSPWiki: through 2.12.3.… | |
| Analizada | Media (6.5) | 0.84% | — | Apache Zeppelin | 30/7/2026 | 5/8/2026 | LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped. This is an incomplete fix of CVE-2024-31867. This issue affects Apache… | |
| Analizada | Media (6.5) | 0.76% | — | Apache Zeppelin | 30/7/2026 | 5/8/2026 | LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint and potentially expose directory information. The role-lookup path was also… | |
| Modificada | Media (6.1) | 0.39% | 💥 PoC | Apache Zeppelin | 30/7/2026 | 7/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a malicious site to perform actions on the user's behalf through REST and… | |
| Analizada | Alta (7.5) | 0.66% | — | Apache Jspwiki | 30/7/2026 | 5/8/2026 | Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue. | |
| Analizada | Alta (8.8) | 0.27% | — | Apache Jspwiki | 30/7/2026 | 5/8/2026 | Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue. | |
| Analizada | Crítica (9.8) | 0.69% | — | Apache Jspwiki | 30/7/2026 | 5/8/2026 | UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue. | |
| Analizada | Alta (7.5) | 0.79% | — | Apache Jspwiki | 30/7/2026 | 5/8/2026 | Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue. |