Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
3889 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.89% | 💥 PoC | Apache Nifi | 8/5/2026 | 17/6/2026 | The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, enabling Groovy Script execution in the… | |
| Modificada | Crítica (9.1) | 0.50% | — | Apache Cloudstack | 8/5/2026 | 17/6/2026 | Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.0.0. The Proxmox extension for CloudStack improperly uses a user-editable instance setting, proxmox_vmid, to associate CloudStack instances… | |
| Modificada | Alta (8.8) | 0.73% | — | Apache Cloudstack | 8/5/2026 | 17/6/2026 | Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file name sanitization, an attacker can register malicious templates to execute arbitrary code on the KVM hosts. This can result in the compromise… | |
| Modificada | Media (5.3) | 0.43% | — | Apache Cloudstack | 8/5/2026 | 7/10/2026 | Debido a múltiples condiciones de carrera de tiempo de verificación y tiempo de uso en la lógica de verificación e incremento del recuento de recursos, así como a validaciones faltantes, los usuarios de la plataforma pueden exceder los límites de asignación configurados para sus cuentas/dominios. Esto puede ser… | |
| Analizada | Alta (8.1) | 0.37% | — | Apache Cloudstack | 8/5/2026 | 7/10/2026 | La falta de limpieza de políticas de MinIO al eliminar un bucket a través de Apache CloudStack permite a los usuarios conservar el acceso a los buckets que poseían anteriormente. Si otro usuario crea un nuevo bucket con el mismo nombre, los propietarios anteriores pueden obtener acceso no autorizado de lectura y… | |
| Analizada | Alta (8.1) | 0.51% | — | Apache Cloudstack | 8/5/2026 | 7/10/2026 | El plugin de copia de seguridad de CloudStack tiene una lógica de acceso inadecuada en las versiones 4.21.0.0 y 4.22.0.0. Cualquier persona con acceso autenticado a una cuenta de usuario en entornos CloudStack 4.21.0.0+, donde este plugin está habilitado y tiene acceso a APIs específicas, puede restaurar un volumen… | |
| Analizada | Media (6.5) | 0.53% | — | Apache Cloudstack | 8/5/2026 | 7/10/2026 | El plugin de CloudStack Backup tiene una lógica de acceso inadecuada en las versiones 4.21.0.0 y 4.22.0.0. Cualquier persona con acceso autenticado a una cuenta de usuario en entornos de CloudStack 4.21.0.0+, donde este plugin está habilitado y tiene acceso a APIs específicas, puede crear nuevas máquinas virtuales… | |
| Analizada | Media (6.5) | 0.49% | — | Apache Cloudstack | 8/5/2026 | 7/10/2026 | El plugin de CloudStack Backup tiene una lógica de autorización impropia en las versiones 4.21.0.0 y 4.22.0.0. Cualquier persona con acceso autenticado a una cuenta de usuario en entornos de CloudStack 4.21.0.0+, donde este plugin está habilitado y tiene acceso a APIs específicas, puede listar copias de seguridad de… | |
| Analizada | Crítica (9.1) | 0.36% | — | Chorny Apache\ | 8/5/2026 | 16/6/2026 | Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted. | |
| Modificada | Crítica (9) | 0.81% | — | Microsoft Azure Managed Instance FOR Apache Cassandra | 7/5/2026 | 17/6/2026 | Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.9) | 0.78% | — | Microsoft Azure Managed Instance FOR Apache Cassandra | 7/5/2026 | 17/6/2026 | Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | |
| Aplazada | Media (5.3) | 0.45% | — | ParquetsharpAIApache ParquetAI | 7/5/2026 | 17/6/2026 | ParquetSharp is a .NET library for reading and writing Apache Parquet files. From version 18.1.0 to before version 23.0.0.1, DecimalConverter.ReadDecimal makes a stackalloc using what might be an attacker-supplied value. If an attacker declares a decimal column with some unreasonable width, this could lead to a stack… | |
| Modificada | Crítica (9.1) | 0.49% | — | Chorny Apache\ | 6/5/2026 | 15/7/2026 | Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the value of the UNIQUE_ID environment variable for the session id. The UNIQUE_ID variable is set by the Apache mod_unique_id plugin, which… | |
| Analizada | Media (6.5) | 1.0% | — | Apache Wicket | 6/5/2026 | 17/6/2026 | FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to write arbitrary files outside the intended upload directory or read files from arbitrary locations on the server. This issue… | |
| Analizada | Alta (7.5) | 0.62% | — | Apache Wicket | 6/5/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes the issue. | |
| Modificada | Media (6.1) | 0.57% | — | Apache Wicket | 6/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes the issue. | |
| Modificada | Crítica (9.1) | 0.61% | — | Apache Wicket | 6/5/2026 | 17/6/2026 | Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes… | |
| Modificada | Crítica (9.8) | 1.6% | — | Apache Http Server | 5/5/2026 | 14/9/2026 | Vulnerabilidad de desbordamiento de búfer basado en montículo en mod_proxy_ajp del Servidor HTTP Apache. Si mod_proxy_ajp se conecta a un servidor AJP malicioso, este servidor AJP puede enviar un mensaje AJP malicioso de vuelta a mod_proxy_ajp y hacer que escriba 4 bytes controlados por el atacante después del final… | |
| Analizada | Alta (7.3) | 1.1% | — | Apache Http Server | 5/5/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. | |
| Analizada | Alta (7.3) | 0.38% | — | Apache Thrift | 5/5/2026 | 17/6/2026 | Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0.… | |
| Modificada | Media (5.3) | 1.2% | — | Apache Thrift | 5/5/2026 | 21/7/2026 | Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Modificada | Alta (7.3) | 0.81% | — | Apache Thrift | 5/5/2026 | 9/9/2026 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Analizada | Crítica (9.4) | 0.59% | — | Apache Polaris | 4/5/2026 | 17/6/2026 | In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells Polaris where to write those metadata files. For a table already registered in a Polaris-managed… | |
| Analizada | Crítica (9.4) | 0.72% | — | Apache Polaris | 4/5/2026 | 17/6/2026 | In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead. Apache Polaris builds Google Cloud Storage downscoped credentials by creating a… | |
| Analizada | Crítica (9.4) | 0.69% | — | Apache Polaris | 4/5/2026 | 17/6/2026 | Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions. In S3 IAM policy matching, `*` is treated as a wildcard… |