Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
3889 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.30% | — | Apache ShiroAI | 25/6/2026 | 25/6/2026 | "Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it indefinitely, even after the configured expiration time has passed. This issue affects all Apache Shiro versions from 1.2.4 through 2.x, and 3.0.0-alpha-1, only when RememberMe… | |
| Aplazada | Alta (8.2) | 0.67% | — | Apache ShiroAIApache Shiro-guiceAI | 25/6/2026 | 25/6/2026 | When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass. This vulnerability is similar to https://www.cve.org/CVERecord?id=CVE-2020-1957 https://www.cve.org/CVERecord , except that it affects the `shiro-guice` module instead of… | |
| Aplazada | Media (6.4) | 0.40% | — | Apache KvrocksAI | 25/6/2026 | 25/6/2026 | A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. | |
| Aplazada | Crítica (10) | 0.48% | — | Apache KvrocksAIRedis LUAAICjsonAI | 25/6/2026 | 25/6/2026 | Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. | |
| Aplazada | Media (5.5) | 0.33% | — | Apache KvrocksAI | 25/6/2026 | 25/6/2026 | A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. | |
| Aplazada | Baja (2.4) | 0.15% | — | Apache KvrocksAI | 25/6/2026 | 25/6/2026 | Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. | |
| Aplazada | Crítica (9.4) | 0.36% | — | Apache KvrocksAI | 25/6/2026 | 25/6/2026 | Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue. | |
| Analizada | Media (6.3) | 0.33% | — | Apache Nifi | 22/6/2026 | 23/6/2026 | Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict values provided in the HTTP Host header,… | |
| Analizada | Alta (7.5) | 0.66% | — | Apache Nifi | 22/6/2026 | 24/6/2026 | Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted… | |
| Analizada | Media (5.2) | 0.65% | — | Apache Nifi | 22/6/2026 | 23/6/2026 | Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover additional… | |
| Analizada | Baja (2.3) | 0.52% | — | Apache Nifi | 22/6/2026 | 23/6/2026 | Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verification methods… | |
| Analizada | Alta (8.1) | 0.56% | — | Apache Doris MCP Server | 22/6/2026 | 6/10/2026 | Apache Doris MCP Server contiene una vulnerabilidad de inyección SQL en una ruta de consulta de metadatos. Un nombre de base de datos controlado por el usuario se interpola directamente en una consulta SQL, y la consulta se ejecuta sin pasar el contexto de autorización del llamante. Esto puede permitir a un atacante… | |
| Analizada | Media (5.4) | 0.51% | — | Apache Atlas | 22/6/2026 | 6/10/2026 | Un usuario autenticado puede realizar XSS. Este problema afecta a las versiones 2.4.0 y anteriores de Apache Atlas. Se recomienda a los usuarios que actualicen a la versión 2.5.0, que corrige el problema. | |
| Aplazada | Crítica (9.4) | 0.23% | — | Line Centraldogma-serverAIApache ZookeeperAI | 22/6/2026 | 22/6/2026 | A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an… | |
| Analizada | Media (5.3) | 0.53% | — | Apache Apisix | 19/6/2026 | 23/6/2026 | Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different source. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the… | |
| Analizada | Baja (2.1) | 0.35% | — | Apache Apisix | 19/6/2026 | 23/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a different identity. Actions the victim takes upstream are… | |
| Analizada | Baja (2.3) | 0.57% | — | Apache Apisix | 19/6/2026 | 23/6/2026 | Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin. This could allow the attacker to assume higher privileges on the upstream service. This issue affects Apache APISIX: from 3.5.0 through… | |
| Analizada | Media (6.3) | 0.30% | 💥 PoC | Apache Apisix | 19/6/2026 | 23/6/2026 | Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass. This issue affects Apache APISIX: from 3.8.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue. | |
| Analizada | Baja (2.1) | 0.65% | — | Apache Apisix | 19/6/2026 | 23/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0,… | |
| Analizada | Media (6.3) | 0.69% | — | Apache Apisix | 19/6/2026 | 23/6/2026 | Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configurations in hmac-auth to re-use a token forever, bypassing expiry. This issue affects Apache APISIX: from 3.11.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue. | |
| Analizada | Media (5.3) | 0.47% | — | Apache Apisix | 19/6/2026 | 23/6/2026 | Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0. Users are recommended to upgrade to version 3.17.0,… | |
| Analizada | Baja (2.1) | 0.64% | — | Apache Apisix | 19/6/2026 | 23/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulnerable to phishing and credential theft. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the… | |
| Analizada | Media (5.3) | 0.28% | — | Apache Apisix | 19/6/2026 | 23/6/2026 | Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack surface that allows the attacker to spoof identity headers allowing the attacker to get unauthorized access the protected resources. This issue affects Apache APISIX: from… | |
| Analizada | Baja (2.3) | 0.47% | — | Apache Apisix | 19/6/2026 | 23/6/2026 | Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed identity information and exploit IP based access control rules. This issue affects Apache APISIX: from 1.2.0 through 3.16.0. Users are… | |
| Analizada | Alta (7) | 0.64% | — | Apache Apisix | 19/6/2026 | 23/6/2026 | Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue. |