Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
3889 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.73% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operation parameter is not set - which is the default. The… | |
| Analizada | Crítica (9.1) | 0.60% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel Solr component. The camel-solr producer copies Exchange message headers whose names begin with the SolrParam. prefix into the… | |
| Analizada | Alta (7.5) | 0.86% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Vertx Websocket component. The camel-vertx-websocket consumer mapped inbound WebSocket query and path parameters into the Camel Exchange header map without applying… | |
| Analizada | Alta (7.5) | 0.63% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf producer selects which SOAP operation to invoke on the backend service from the operationName (and operationNamespace) Exchange header, whose constant values… | |
| Analizada | Alta (8.2) | 0.55% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-2025-66169 addressed Cypher injection through the property… | |
| Analizada | Alta (8.8) | 0.84% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. HashicorpVaultKeyLifecycleManager and AwsSecretsManagerKeyLifecycleManager read that metadata back from the… | |
| Analizada | Alta (7.5) | 0.63% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene producer reads the search phrase from an Exchange header (LuceneConstants.HEADER_QUERY) whose value was the plain string QUERY (and RETURN_LUCENE_DOCS for… | |
| Analizada | Baja (3.7) | 0.56% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Camel Mail Component. The camel-mail producer (MailProducer.getSender) scanned the outgoing Exchange for message headers in the mail.smtp. / mail.smtps. namespace and, when any were present, built a… | |
| Analizada | Alta (7.5) | 0.66% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS message headers into the Camel Exchange but defaulted its headerFilterStrategy to a bare new DefaultHeaderFilterStrategy() with no inbound rules configured (NatsConfiguration). With no inFilter,… | |
| Analizada | Crítica (9.8) | 0.79% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes into the Camel Exchange through a component-specific HeaderFilterStrategy. Sqs2HeaderFilterStrategy configured only an outbound filter (setOutFilterPattern, which blocks Camel*,… | |
| Analizada | Crítica (9.8) | 0.69% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Keycloak TokenVerifier using withChecks(...) with only the subject-exists check and the realm-URL (issuer) check. Keycloak's… | |
| Analizada | Crítica (9.8) | 0.83% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers into the Camel Exchange without applying a HeaderFilterStrategy. CometdBinding.populateExchangeFromMessage copies the entire ext.CamelHeaders map supplied by the CometD… | |
| Analizada | Media (5.3) | 0.55% | 💥 PoC | Apache Camel | 6/7/2026 | 7/7/2026 | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elasticsearch-rest-client component reads several Exchange headers to control its behaviour - SEARCH_QUERY (an advanced query body), OPERATION (which Elasticsearch operation to… | |
| Analizada | Crítica (9.8) | 0.93% | 💥 PoC | Apache Camel | 6/7/2026 | 7/7/2026 | Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. AwsSecretsManagerKeyLifecycleManager.deserializeMetadata() reads that metadata back from the configured AWS… | |
| Analizada | Alta (7.3) | 0.65% | 💥 PoC | Apache Camel | 6/7/2026 | 7/7/2026 | Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms() in camel-jms - and the equivalent JmsBinding in camel-sjms - deserializes the payload of an incoming JMS ObjectMessage via jakarta.jms.ObjectMessage.getObject() whenever the mapJmsMessage option… | |
| Analizada | Alta (8.1) | 0.98% | 💥 PoC | Apache Camel | 6/7/2026 | 7/7/2026 | Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. When Camel builds the Hazelcast Config itself - that is, when no user-supplied… | |
| Analizada | Alta (8.1) | 0.67% | 💥 PoC | Apache Camel | 6/7/2026 | 7/7/2026 | Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' variant in the aggregation-repository components) uses a… | |
| Analizada | Alta (8.1) | 0.89% | 💥 PoC | Apache Camel | 6/7/2026 | 7/7/2026 | Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any ObjectInputFilter… | |
| Analizada | Crítica (9.1) | 2.4% | 💥 PoC | Apache Camel | 6/7/2026 | 8/7/2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external `docling` command-line tool by assembling an argument list in DoclingProducer and executing it through java.lang.ProcessBuilder. Custom… | |
| Analizada | Crítica (9.8) | 0.69% | — | Apache Iotdb | 6/7/2026 | 7/7/2026 | Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside… | |
| Analizada | Crítica (9.1) | 0.64% | — | Apache Iotdb | 6/7/2026 | 7/7/2026 | Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results. This allows authentication… | |
| Analizada | Alta (7.5) | 0.74% | — | Apache Iotdb | 6/7/2026 | 7/7/2026 | Uncontrolled Resource Consumption vulnerability in Apache IoTDB. Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g., a very large time range combined with a minimal interval). This forces the… | |
| Analizada | Alta (8.9) | 0.81% | — | Apache Lucene.net | 3/7/2026 | 8/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta00017. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the… | |
| Analizada | Media (4) | 0.47% | — | Apache Lucene.net | 3/7/2026 | 8/7/2026 | Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue. | |
| Analizada | Alta (8.9) | 0.72% | — | Apache Lucene.net | 3/7/2026 | 8/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the… |