Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 4.5% | — | Apache ActivemqOracle Communications Diameter Signaling RouterOracle Flexcube Private BankingDebian Linux | 10/9/2020 | 17/6/2026 | Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original,… | |
| Modificada | Crítica (9.8) | 49% | 💥 PoC | Apache ActivemqOracle Communications Diameter Signaling RouterOracle Communications Element ManagerOracle Communications Session Report Manager+3 | 10/9/2020 | 17/6/2026 | A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack:… | |
| Modificada | Media (6.1) | 7.1% | — | Apache ActivemqOracle Communications Diameter Signaling RouterOracle Communications Element ManagerOracle Communications Session Report Manager+3 | 14/5/2020 | 17/6/2026 | In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue. | |
| Modificada | Baja (2.7) | 2.0% | — | Apache ActivemqRedhat Jboss A-mqRedhat Jboss Fuse | 1/8/2019 | 17/6/2026 | It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client. | |
| Modificada | Media (5.9) | 9.7% | — | Apache ActivemqApache DrillApache ZookeeperDebian Linux+6 | 23/5/2019 | 17/6/2026 | An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id… | |
| Analizada | Crítica (9.8) | 84% | 💥 Exploit | Oracle Endeca Information Discovery StudioApache ActivemqXstream | 15/5/2019 | 17/6/2026 | Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON. | |
| Modificada | Media (6.1) | 9.4% | — | Eclipse JettyDebian LinuxApache ActivemqApache Drill+3 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents. | |
| Modificada | Alta (7.5) | 12% | 💥 PoC | Apache ActivemqNetapp E-series Santricity WEB ServicesOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base Platform+4 | 28/3/2019 | 17/6/2026 | In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive. | |
| Modificada | Media (6.1) | 55% | 💥 Exploit | Apache Activemq | 10/10/2018 | 17/6/2026 | An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter. | |
| Modificada | Alta (7.4) | 7.0% | — | Apache ActivemqOracle Enterprise RepositoryOracle Flexcube Private Banking | 10/9/2018 | 17/6/2026 | TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default. | |
| Modificada | Baja (3.7) | 23% | — | Apache Activemq | 13/2/2018 | 17/6/2026 | When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text. | |
| Modificada | Media (6.1) | 6.1% | — | Apache Activemq | 10/1/2018 | 17/6/2026 | In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation. | |
| Modificada | Crítica (9.8) | 9.7% | — | Apache Activemq | 27/10/2017 | 17/6/2026 | XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages. | |
| Modificada | Crítica (9.8) | 4.6% | — | Apache Activemq Apollo | 27/10/2017 | 17/6/2026 | XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages. | |
| Modificada | Media (5.4) | 6.1% | — | Apache Activemq | 5/8/2016 | 17/6/2026 | The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Apache Activemq | 1/6/2016 | 17/6/2026 | The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request. | |
| Modificada | Media (6.1) | 8.6% | — | Apache Activemq | 7/4/2016 | 17/6/2026 | The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element. | |
| Modificada | Crítica (9.8) | 38% | 💥 PoC | Redhat OpenshiftApache ActivemqFedoraproject Fedora | 8/1/2016 | 17/6/2026 | Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object. | |
| Modificada | Media (5) | 8.6% | — | Fedoraproject FedoraApache Activemq | 24/8/2015 | 17/6/2026 | The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to… | |
| Modificada | Alta (7.5) | 7.2% | — | Apache Activemq | 24/8/2015 | 17/6/2026 | The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per… | |
| Modificada | Media (5) | 84% | 💥 Exploit | Apache Activemq | 19/8/2015 | 17/6/2026 | Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors. | |
| Modificada | Alta (7.5) | 13% | 💥 PoC | Apache ActivemqOracle Business Intelligence PublisherOracle Fusion Middleware | 14/8/2015 | 17/6/2026 | The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command. | |
| Modificada | Media (4.3) | 7.1% | 💥 PoC | Apache Activemq | 12/2/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 6.8% | — | Apache Activemq | 5/2/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092. | |
| Modificada | Media (4.3) | 6.6% | — | Apache Activemq | 20/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message." |