Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

3889 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.8)0.68%—Apache Apisix19/6/202623/6/2026
Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
AplazadaCrítica (10)0.93%—Mcp-pinotAIApache PinotAI18/6/202623/6/2026
mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP server bound to 0.0.0.0:8080 with no authentication enabled. All MCP tools, including SQL query execution, schema creation, and table-config…
AnalizadaAlta (8.8)0.76%💥 PoCApache Shiro17/6/202618/6/2026
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used…
AnalizadaCrítica (9.1)0.88%—Apache-airflow-providers-sftp17/6/202617/6/2026
A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment…
ModificadaMedia (6.5)0.55%—Apache Dolphinscheduler17/6/202617/6/2026
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
ModificadaMedia (6.5)0.49%—Apache Dolphinscheduler17/6/202617/6/2026
Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.
AnalizadaMedia (4.9)0.54%—Apache Dolphinscheduler17/6/202617/6/2026
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.
ModificadaCrítica (9.1)0.55%—Apache Dolphinscheduler17/6/202617/6/2026
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
ModificadaCrítica (9.8)0.66%—Apache Dolphinscheduler17/6/202617/6/2026
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
ModificadaAlta (7.5)0.74%—Apache CXF12/6/20267/8/2026
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue by imposing a…
ModificadaMedia (6.5)0.36%—Apache CXF12/6/20267/8/2026
A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-header metadata came from a verified signature entry, and may…
ModificadaAlta (8.1)1.3%—Apache CXF12/6/20267/8/2026
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes…
ModificadaAlta (8.1)1.1%—Apache CXF12/6/20267/8/2026
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or…
ModificadaAlta (7.4)0.39%—Apache CXF12/6/20267/8/2026
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are…
ModificadaMedia (6.5)0.64%—Apache CXF12/6/20267/8/2026
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inject arbitrary HTTP…
ModificadaMedia (5.3)0.70%—Apache CXF12/6/20267/8/2026
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2…
ModificadaCrítica (9.8)1.0%—Apache CXF12/6/20267/8/2026
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which…
ModificadaCrítica (9.1)0.78%—Apache CXF12/6/20267/8/2026
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to…
ModificadaMedia (4.8)0.54%—Apache CXF12/6/20267/8/2026
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard…
ModificadaCrítica (9.8)0.81%—Apache CXF12/6/20267/8/2026
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue.
AnalizadaAlta (8.8)1.1%—Apache Ofbiz10/6/202623/7/2026
La vulnerabilidad de Control Inadecuado de la Generación de Código ('Inyección de Código') en Apache OFBiz permite a un usuario autenticado con bajos privilegios y con privilegios de edición de Contenido/Recursos de Datos realizar ataques de inyección de plantillas que podrían conducir a la Ejecución Remota de Código.…
AnalizadaAlta (8.8)0.58%—Apache Ofbiz10/6/202623/7/2026
Una vulnerabilidad de escalada de privilegios en Apache OFBiz permite a un usuario autenticado con bajos privilegios obtener privilegios superiores. Este problema afecta a Apache OFBiz: versiones anteriores a la 24.09.07. Se recomienda a los usuarios actualizar a la versión 24.09.07, que corrige el problema.
AplazadaAlta (8.1)0.49%—ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI10/6/202617/6/2026
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules/config/config.py:462. This is tuple-membership, not substring…
AplazadaAlta (8.3)0.40%—ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI10/6/202617/6/2026
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches.
AplazadaMedia (6.1)0.26%—ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI10/6/202617/6/2026
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next URLs by rejecting strings containing https:// or http:// substrings, then constructs https://{request.host}{next_url} and the JS client redirects via…