Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

3889 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.87%—Apache Httpcomponents Core1/7/202624/7/2026
Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS…
AnalizadaAlta (7.5)0.87%—Apache Httpcomponents Core1/7/202624/7/2026
Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length
AplazadaMedia (6.3)0.48%—Apache Commons-beanutilsAIMchange C3p0AI30/6/20262/7/2026
c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSource.getPooledConnection() match the getXXX() form, so JavaBean libraries treat them…
AnalizadaMedia (5.4)0.56%—Apache Gravitino30/6/202629/9/2026
Una mala configuración de SQL en la interfaz de usuario de Gravitino, en las versiones 1.0.0 e inferiores, puede permitir a un usuario malintencionado leer o truncar archivos. Se recomienda a los usuarios actualizar a la versión 1.0.0, que soluciona este problema.
AnalizadaAlta (7.5)0.56%—Apache ActivemqApache Activemq Broker30/6/20262/7/2026
Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only checked in the client, allowing a different connection to…
AnalizadaAlta (7.5)0.74%—Apache ActivemqApache Activemq Broker30/6/20262/7/2026
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker. An authenticated user can cause a broker DoS by sending a crafted OpenWire Message with a large encoded size value for the map. OpenWire message property maps are…
AnalizadaAlta (7.5)0.74%—Apache Activemq30/6/20262/7/2026
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. An unauthenticated client that opens a STOMP NIO connection can send header bytes that never terminate which makes the broker buffer them without limit, exhausting the JVM heap. This issue affects…
AnalizadaMedia (6.1)0.68%—Apache ActivemqApache Activemq WEB30/6/20262/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an authenticated producer to send a message with a JMS message ID that…
AnalizadaAlta (7.5)0.69%—Apache ActivemqApache Activemq Broker30/6/20262/7/2026
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without sending a ConnectionInfo, until the broker will crash with OOM.…
AnalizadaAlta (7.5)0.74%—Apache Activemq30/6/20262/7/2026
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt…
AnalizadaAlta (8.1)0.51%—Apache Activemq30/6/20262/7/2026
Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7.…
AnalizadaAlta (7.5)0.63%—Apache ActivemqApache Activemq Broker30/6/20262/7/2026
Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker…
AnalizadaAlta (7.5)0.78%—Apache Activemq30/6/20262/7/2026
Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body…
AnalizadaAlta (7.3)2.9%💥 PoCApache Tomcat29/6/20262/7/2026
Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from…
AnalizadaMedia (6.5)0.69%—Apache Tomcat29/6/20262/7/2026
Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through…
AnalizadaMedia (6.5)0.44%—Apache Tomcat29/6/202610/7/2026
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through…
AnalizadaCrítica (9.1)0.61%—Apache Tomcat29/6/20262/7/2026
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through…
AnalizadaCrítica (9.1)0.59%—Apache Tomcat29/6/20262/7/2026
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or…
AnalizadaAlta (7.3)0.65%—Apache Tomcat29/6/20262/7/2026
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through…
AnalizadaMedia (6.1)4.1%💥 ExploitApache Tomcat29/6/20262/7/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through…
AplazadaAlta (7.3)0.53%—Apache KerbyAI26/6/20263/8/2026
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
AplazadaMedia (6.5)0.44%—Apache KerbyAI26/6/202626/6/2026
By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
AplazadaCrítica (9.1)0.54%—Apache IotdbAI26/6/202629/9/2026
Limitación incorrecta de un nombre de ruta a un directorio restringido ('Salto de ruta') vulnerabilidad en Apache IoTDB. Este problema afecta a Apache IoTDB: desde 1.0.0 anterior a 1.3.6, desde 2.0.0 anterior a 2.0.7. Se recomienda a los usuarios actualizar a la versión 1.3.6 y 2.0.7, que corrige el problema.
AplazadaCrítica (9.1)0.54%—Apache IotdbAI26/6/202629/9/2026
Vulnerabilidad de Limitación Inadecuada de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') en Apache IoTDB. Este problema afecta a Apache IoTDB: desde 2.0.0 antes de 2.0.6, desde 1.0.0 antes de 1.3.6. Se recomienda a los usuarios actualizar a las versiones 1.3.6 y 2.0.6, lo que soluciona el problema.
ModificadaAlta (7.5)0.44%—Apache-airflow-providers-ftp26/6/202616/9/2026
The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTPSFileTransmitOperator` to move files over FTPS exposed file…