Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.6) | 0.85% | — | Apache Opennlp | 24/7/2026 | 6/8/2026 | Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three code paths in Apache OpenNLP load a class by its fully-qualified name via Class.forName() and invoke its no-arg constructor without any prior… | |
| Analizada | Alta (7.3) | 0.68% | — | Apache Fory | 21/7/2026 | 27/7/2026 | Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommended to upgrade to version 1.4.0, which fixes the issue. | |
| Analizada | Crítica (9.8) | 0.78% | — | Apache Fory | 21/7/2026 | 27/7/2026 | Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue. | |
| Analizada | Crítica (9.1) | 0.78% | — | Apache Fory | 21/7/2026 | 27/7/2026 | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that do not use it are not affected. This issue affects Apache… | |
| Analizada | Crítica (9.8) | 0.81% | — | Apache Fory | 21/7/2026 | 11/8/2026 | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory… | |
| Analizada | Media (5.4) | 0.64% | — | Apache Mina Sshd | 20/7/2026 | 27/7/2026 | Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though its GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that SSH clients can remotely execute git commands via the… | |
| Analizada | Alta (7.3) | 0.29% | — | Apache Mina Sshd | 20/7/2026 | 27/7/2026 | Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or verify-required options… | |
| Analizada | Alta (7.1) | 0.87% | — | Apache Mina Sshd | 20/7/2026 | 27/7/2026 | Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an authenticated remote user access to git repositories outside of the… | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Mina Sshd | 20/7/2026 | 27/7/2026 | Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting… | |
| Analizada | Crítica (9.8) | 0.75% | — | Apache Syncope | 20/7/2026 | 27/7/2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0… | |
| Analizada | Alta (8.1) | 0.47% | — | Apache Syncope | 20/7/2026 | 27/7/2026 | Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which… | |
| Analizada | Crítica (9.8) | 0.69% | 💥 PoC | Apache Syncope | 20/7/2026 | 27/7/2026 | Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update requests the following scenario could happen.… | |
| Analizada | Crítica (9.8) | 0.83% | — | Apache Syncope | 20/7/2026 | 27/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through… | |
| Analizada | Crítica (9.8) | 1.1% | — | Apache Syncope | 20/7/2026 | 27/7/2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This issue affects Apache Syncope: from 3.0.0-M0… | |
| Analizada | Crítica (9.8) | 0.75% | — | Apache Syncope | 20/7/2026 | 27/7/2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed… | |
| Analizada | Alta (7.5) | 0.74% | — | Apache Traffic Server | 18/7/2026 | 6/8/2026 | Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue. | |
| Analizada | Media (5.7) | 0.79% | — | Apache Accumulo | 17/7/2026 | 11/8/2026 | Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver), leading to a denial of… | |
| Aplazada | Alta (7.5) | 0.45% | — | ApacheAIWwbn AvideoAI | 16/7/2026 | 17/7/2026 | WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The official docker-compose.yml mounts the entire project root directory as the Apache document root, causing the .env file — which contains database… | |
| Analizada | Media (5.4) | 0.70% | — | Apache IVY | 15/7/2026 | 16/7/2026 | The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured "buildRoot" directory. This subdirectory is calculated based on modules coordinates,… | |
| Analizada | Alta (8.1) | 0.74% | 💥 PoC | Apache Fineract | 15/7/2026 | 15/7/2026 | A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL… | |
| Analizada | Alta (8.1) | 0.65% | — | Apache Fineract | 15/7/2026 | 15/7/2026 | A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view… | |
| Analizada | Alta (8.8) | 3.3% | — | Apache Fineract | 15/7/2026 | 15/7/2026 | A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject… | |
| Modificada | Media (4.3) | 0.45% | — | Apache Kylin | 14/7/2026 | 15/7/2026 | Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version… | |
| Modificada | Crítica (9.8) | 2.5% | — | Apache Kylin | 14/7/2026 | 15/7/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue. | |
| Modificada | Crítica (9.8) | 0.69% | — | Apache Kylin | 14/7/2026 | 14/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes… |