Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
3889 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.8) | 0.68% | — | Apache Apisix | 19/6/2026 | 23/6/2026 | Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue. | |
| Aplazada | Crítica (10) | 0.93% | — | Mcp-pinotAIApache PinotAI | 18/6/2026 | 23/6/2026 | mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP server bound to 0.0.0.0:8080 with no authentication enabled. All MCP tools, including SQL query execution, schema creation, and table-config… | |
| Analizada | Alta (8.8) | 0.76% | 💥 PoC | Apache Shiro | 17/6/2026 | 18/6/2026 | A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used… | |
| Analizada | Crítica (9.1) | 0.88% | — | Apache-airflow-providers-sftp | 17/6/2026 | 17/6/2026 | A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment… | |
| Modificada | Media (6.5) | 0.55% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Modificada | Media (6.5) | 0.49% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue. | |
| Analizada | Media (4.9) | 0.54% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue. | |
| Modificada | Crítica (9.1) | 0.55% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Modificada | Crítica (9.8) | 0.66% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Modificada | Alta (7.5) | 0.74% | — | Apache CXF | 12/6/2026 | 7/8/2026 | There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue by imposing a… | |
| Modificada | Media (6.5) | 0.36% | — | Apache CXF | 12/6/2026 | 7/8/2026 | A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-header metadata came from a verified signature entry, and may… | |
| Modificada | Alta (8.1) | 1.3% | — | Apache CXF | 12/6/2026 | 7/8/2026 | A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes… | |
| Modificada | Alta (8.1) | 1.1% | — | Apache CXF | 12/6/2026 | 7/8/2026 | A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or… | |
| Modificada | Alta (7.4) | 0.39% | — | Apache CXF | 12/6/2026 | 7/8/2026 | A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are… | |
| Modificada | Media (6.5) | 0.64% | — | Apache CXF | 12/6/2026 | 7/8/2026 | A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inject arbitrary HTTP… | |
| Modificada | Media (5.3) | 0.70% | — | Apache CXF | 12/6/2026 | 7/8/2026 | The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2… | |
| Modificada | Crítica (9.8) | 1.0% | — | Apache CXF | 12/6/2026 | 7/8/2026 | A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which… | |
| Modificada | Crítica (9.1) | 0.78% | — | Apache CXF | 12/6/2026 | 7/8/2026 | The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to… | |
| Modificada | Media (4.8) | 0.54% | — | Apache CXF | 12/6/2026 | 7/8/2026 | An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard… | |
| Modificada | Crítica (9.8) | 0.81% | — | Apache CXF | 12/6/2026 | 7/8/2026 | Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue. | |
| Analizada | Alta (8.8) | 1.1% | — | Apache Ofbiz | 10/6/2026 | 23/7/2026 | La vulnerabilidad de Control Inadecuado de la Generación de Código ('Inyección de Código') en Apache OFBiz permite a un usuario autenticado con bajos privilegios y con privilegios de edición de Contenido/Recursos de Datos realizar ataques de inyección de plantillas que podrían conducir a la Ejecución Remota de Código.… | |
| Analizada | Alta (8.8) | 0.58% | — | Apache Ofbiz | 10/6/2026 | 23/7/2026 | Una vulnerabilidad de escalada de privilegios en Apache OFBiz permite a un usuario autenticado con bajos privilegios obtener privilegios superiores. Este problema afecta a Apache OFBiz: versiones anteriores a la 24.09.07. Se recomienda a los usuarios actualizar a la versión 24.09.07, que corrige el problema. | |
| Aplazada | Alta (8.1) | 0.49% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules/config/config.py:462. This is tuple-membership, not substring… | |
| Aplazada | Alta (8.3) | 0.40% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches. | |
| Aplazada | Media (6.1) | 0.26% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next URLs by rejecting strings containing https:// or http:// substrings, then constructs https://{request.host}{next_url} and the JS client redirects via… |