Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
3872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 5/10/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 5/10/2026 | Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 5/10/2026 | Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 5/10/2026 | Uncaught exception vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.46% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Crítica (9.2) | 0.46% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer… | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings. This… | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Media (6.3) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 5/10/2026 | improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Sin puntuar | 0.20% | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to… | |
| Aplazada | Alta (7.5) | 0.49% | — | Apache Directory Ldap APIAI | 2/10/2026 | 5/10/2026 | Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS.… | |
| Aplazada | Alta (7.5) | 0.21% | — | Apache Directory Ldap APIAI | 2/10/2026 | 5/10/2026 | Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed. This issue affects Apache Directory LDAP API: from 2.1.0 before… | |
| Aplazada | Sin puntuar | 0.39% | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE. This issue affects Apache Directory LDAP API: from… | |
| Aplazada | Alta (7.3) | 0.34% | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue. | |
| Aplazada | Alta (7.5) | 0.43% | — | Apache Directory Ldap APIAI | 2/10/2026 | 5/10/2026 | Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service. The client JVM OOMs (OutOfMemoryError… | |
| Analizada | Alta (8.8) | 0.44% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces. | |
| Analizada | Media (5.3) | 0.59% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. |