Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

3889 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)1.2%—Apache Thrift28/4/20269/9/2026
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
ModificadaAlta (7.5)1.4%—Apache Thrift28/4/20269/9/2026
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
ModificadaAlta (7.5)1.1%—Apache Thrift28/4/20267/10/2026
Vulnerabilidad de rutinas de gestión de memoria desajustadas en los enlaces de lenguaje c_glib de Apache Thrift. Este problema afecta a Apache Thrift: anterior a 0.23.0. Se recomienda a los usuarios actualizar a la versión 0.23.0, que soluciona el problema. Descripción: Solicitudes especialmente diseñadas pueden…
AnalizadaMedia (6.5)0.45%—Apache Storm27/4/202617/6/2026
Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (the default configuration), the TlsTransportPlugin assigns a…
AnalizadaMedia (4.8)0.28%—Apache Storm Prometheus Reporter27/4/202617/6/2026
Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description: In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it is disabled) intending to…
ModificadaCrítica (10)7.2%💥 ExploitApache Camel27/4/202615/7/2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when routes forward CoAP requests to header-sensitive producers (e.g.…
ModificadaAlta (8.8)1.1%💥 PoCApache Camel27/4/202615/7/2026
The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserialize method) read Java-serialized values from the Consul KV store and passed them to ObjectInputStream.readObject() without configuring an ObjectInputFilter. An attacker who…
AnalizadaCrítica (9.8)0.75%—Apache Mina27/4/202617/6/2026
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Affected versions are Apache MINA 2.0.0 <= 2.0.27, 2.1.0 <=…
ModificadaAlta (8.8)1.2%💥 PoCApache Camel27/4/20269/9/2026
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel application can inject a crafted serialized…
ModificadaAlta (8.2)1.0%💥 PoCApache Camel27/4/202615/7/2026
When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or camel.management.path, the BasicAuthenticationConfigurer and JWTAuthenticationConfigurer classes…
ModificadaCrítica (9.4)1.0%💥 PoCApache Camel27/4/202615/7/2026
The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the 'in' direction via setInFilterStartsWith. As a result, when a Camel…
AnalizadaCrítica (9.8)0.82%—Apache Mina27/4/202617/6/2026
Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the class is present in the accepted class filter before calling…
ModificadaCrítica (9.8)1.5%💥 PoCApache Camel27/4/20269/9/2026
JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or class denylist. Because this code path is reached whenever…
ModificadaAlta (8.8)1.1%💥 PoCApache Camel27/4/202615/7/2026
The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP consumer and requests conversion to ObjectInput (for example via…
ModificadaCrítica (9.9)1.9%💥 PoCApache Camel27/4/202615/7/2026
The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to five non-HTTP HeaderFilterStrategy implementations:…
ModificadaAlta (7.8)0.46%💥 PoCApache Camel27/4/202615/7/2026
The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cast to `java.security.KeyPair` is evaluated only after `readObject()` has already…
AplazadaCrítica (9.3)1.1%—Apache Axis2AISangoma FilestoreAI24/4/202617/6/2026
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default…
AnalizadaMedia (4.3)0.57%—Apache Airflow24/4/202617/6/2026
The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside their authorized scope. Users are recommended to upgrade to…
AnalizadaMedia (4.3)0.57%—Apache Airflow24/4/202617/6/2026
The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL prompts (including their request parameters) and full TaskInstance details for DAGs outside their…
AnalizadaAlta (8.1)0.45%—Apache Dolphinscheduler24/4/202617/6/2026
Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1. Users are recommended to upgrade to version 3.4.1,…
ModificadaAlta (8.8)1.1%💥 PoCApache ActivemqApache Activemq Broker24/4/202615/7/2026
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. An authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validation to include an xbean binding…
AnalizadaMedia (6.5)0.72%—Apache ActivemqApache Activemq WEB24/4/202617/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS…
ModificadaAlta (8.8)4.1%💥 ExploitApache ActivemqApache Activemq Broker24/4/202615/7/2026
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerView.addNetworkConnector…
AnalizadaMedia (6.3)0.54%—Apache Dolphinscheduler24/4/20267/10/2026
Vulnerabilidad de deserialización de datos no confiables en el módulo RPC de Apache DolphinScheduler. Este problema afecta a Apache DolphinScheduler: Versión >= 3.2.0 y menor que 3.3.1. Los atacantes que pueden acceder a los nodos Master o Worker pueden comprometer el sistema creando un StandardRpcRequest, inyectando…
Pendiente de análisisAlta (7.5)1.2%💥 PoCApache CamelAIInfinispanAI22/4/202623/9/2026
A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over…