Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

83 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)4.5%—Apache ActivemqOracle Communications Diameter Signaling RouterOracle Flexcube Private BankingDebian Linux10/9/202017/6/2026
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original,…
ModificadaCrítica (9.8)49%💥 PoCApache ActivemqOracle Communications Diameter Signaling RouterOracle Communications Element ManagerOracle Communications Session Report Manager+310/9/202017/6/2026
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack:…
ModificadaMedia (6.1)7.1%—Apache ActivemqOracle Communications Diameter Signaling RouterOracle Communications Element ManagerOracle Communications Session Report Manager+314/5/202017/6/2026
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
ModificadaBaja (2.7)2.0%—Apache ActivemqRedhat Jboss A-mqRedhat Jboss Fuse1/8/201917/6/2026
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.
ModificadaMedia (5.9)9.7%—Apache ActivemqApache DrillApache ZookeeperDebian Linux+623/5/201917/6/2026
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id…
AnalizadaCrítica (9.8)84%💥 ExploitOracle Endeca Information Discovery StudioApache ActivemqXstream15/5/201917/6/2026
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
ModificadaMedia (6.1)9.4%—Eclipse JettyDebian LinuxApache ActivemqApache Drill+322/4/201917/6/2026
In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.
ModificadaAlta (7.5)12%💥 PoCApache ActivemqNetapp E-series Santricity WEB ServicesOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base Platform+428/3/201917/6/2026
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
ModificadaMedia (6.1)55%💥 ExploitApache Activemq10/10/201817/6/2026
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.
ModificadaAlta (7.4)7.0%—Apache ActivemqOracle Enterprise RepositoryOracle Flexcube Private Banking10/9/201817/6/2026
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.
ModificadaBaja (3.7)23%—Apache Activemq13/2/201817/6/2026
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
ModificadaMedia (6.1)6.1%—Apache Activemq10/1/201817/6/2026
In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.
ModificadaCrítica (9.8)9.7%—Apache Activemq27/10/201717/6/2026
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
ModificadaCrítica (9.8)4.6%—Apache Activemq Apollo27/10/201717/6/2026
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
ModificadaMedia (5.4)6.1%—Apache Activemq5/8/201617/6/2026
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitApache Activemq1/6/201617/6/2026
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
ModificadaMedia (6.1)8.6%—Apache Activemq7/4/201617/6/2026
The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
ModificadaCrítica (9.8)38%💥 PoCRedhat OpenshiftApache ActivemqFedoraproject Fedora8/1/201617/6/2026
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
ModificadaMedia (5)8.6%—Fedoraproject FedoraApache Activemq24/8/201517/6/2026
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to…
ModificadaAlta (7.5)7.2%—Apache Activemq24/8/201517/6/2026
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per…
ModificadaMedia (5)84%💥 ExploitApache Activemq19/8/201517/6/2026
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.
ModificadaAlta (7.5)13%💥 PoCApache ActivemqOracle Business Intelligence PublisherOracle Fusion Middleware14/8/201517/6/2026
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
ModificadaMedia (4.3)7.1%💥 PoCApache Activemq12/2/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)6.8%—Apache Activemq5/2/201416/6/2026
Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092.
ModificadaMedia (4.3)6.6%—Apache Activemq20/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."
Orbitaley — Vulnerabilidades