Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
3889 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 1.2% | — | Apache Thrift | 28/4/2026 | 9/9/2026 | Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Modificada | Alta (7.5) | 1.4% | — | Apache Thrift | 28/4/2026 | 9/9/2026 | Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Modificada | Alta (7.5) | 1.1% | — | Apache Thrift | 28/4/2026 | 7/10/2026 | Vulnerabilidad de rutinas de gestión de memoria desajustadas en los enlaces de lenguaje c_glib de Apache Thrift. Este problema afecta a Apache Thrift: anterior a 0.23.0. Se recomienda a los usuarios actualizar a la versión 0.23.0, que soluciona el problema. Descripción: Solicitudes especialmente diseñadas pueden… | |
| Analizada | Media (6.5) | 0.45% | — | Apache Storm | 27/4/2026 | 17/6/2026 | Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (the default configuration), the TlsTransportPlugin assigns a… | |
| Analizada | Media (4.8) | 0.28% | — | Apache Storm Prometheus Reporter | 27/4/2026 | 17/6/2026 | Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description: In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it is disabled) intending to… | |
| Modificada | Crítica (10) | 7.2% | 💥 Exploit | Apache Camel | 27/4/2026 | 15/7/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when routes forward CoAP requests to header-sensitive producers (e.g.… | |
| Modificada | Alta (8.8) | 1.1% | 💥 PoC | Apache Camel | 27/4/2026 | 15/7/2026 | The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserialize method) read Java-serialized values from the Consul KV store and passed them to ObjectInputStream.readObject() without configuring an ObjectInputFilter. An attacker who… | |
| Analizada | Crítica (9.8) | 0.75% | — | Apache Mina | 27/4/2026 | 17/6/2026 | The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Affected versions are Apache MINA 2.0.0 <= 2.0.27, 2.1.0 <=… | |
| Modificada | Alta (8.8) | 1.2% | 💥 PoC | Apache Camel | 27/4/2026 | 9/9/2026 | The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel application can inject a crafted serialized… | |
| Modificada | Alta (8.2) | 1.0% | 💥 PoC | Apache Camel | 27/4/2026 | 15/7/2026 | When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or camel.management.path, the BasicAuthenticationConfigurer and JWTAuthenticationConfigurer classes… | |
| Modificada | Crítica (9.4) | 1.0% | 💥 PoC | Apache Camel | 27/4/2026 | 15/7/2026 | The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the 'in' direction via setInFilterStartsWith. As a result, when a Camel… | |
| Analizada | Crítica (9.8) | 0.82% | — | Apache Mina | 27/4/2026 | 17/6/2026 | Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the class is present in the accepted class filter before calling… | |
| Modificada | Crítica (9.8) | 1.5% | 💥 PoC | Apache Camel | 27/4/2026 | 9/9/2026 | JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or class denylist. Because this code path is reached whenever… | |
| Modificada | Alta (8.8) | 1.1% | 💥 PoC | Apache Camel | 27/4/2026 | 15/7/2026 | The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP consumer and requests conversion to ObjectInput (for example via… | |
| Modificada | Crítica (9.9) | 1.9% | 💥 PoC | Apache Camel | 27/4/2026 | 15/7/2026 | The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to five non-HTTP HeaderFilterStrategy implementations:… | |
| Modificada | Alta (7.8) | 0.46% | 💥 PoC | Apache Camel | 27/4/2026 | 15/7/2026 | The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cast to `java.security.KeyPair` is evaluated only after `readObject()` has already… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Apache Axis2AISangoma FilestoreAI | 24/4/2026 | 17/6/2026 | BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default… | |
| Analizada | Media (4.3) | 0.57% | — | Apache Airflow | 24/4/2026 | 17/6/2026 | The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside their authorized scope. Users are recommended to upgrade to… | |
| Analizada | Media (4.3) | 0.57% | — | Apache Airflow | 24/4/2026 | 17/6/2026 | The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL prompts (including their request parameters) and full TaskInstance details for DAGs outside their… | |
| Analizada | Alta (8.1) | 0.45% | — | Apache Dolphinscheduler | 24/4/2026 | 17/6/2026 | Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1. Users are recommended to upgrade to version 3.4.1,… | |
| Modificada | Alta (8.8) | 1.1% | 💥 PoC | Apache ActivemqApache Activemq Broker | 24/4/2026 | 15/7/2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. An authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validation to include an xbean binding… | |
| Analizada | Media (6.5) | 0.72% | — | Apache ActivemqApache Activemq WEB | 24/4/2026 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS… | |
| Modificada | Alta (8.8) | 4.1% | 💥 Exploit | Apache ActivemqApache Activemq Broker | 24/4/2026 | 15/7/2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerView.addNetworkConnector… | |
| Analizada | Media (6.3) | 0.54% | — | Apache Dolphinscheduler | 24/4/2026 | 7/10/2026 | Vulnerabilidad de deserialización de datos no confiables en el módulo RPC de Apache DolphinScheduler. Este problema afecta a Apache DolphinScheduler: Versión >= 3.2.0 y menor que 3.3.1. Los atacantes que pueden acceder a los nodos Master o Worker pueden comprometer el sistema creando un StandardRpcRequest, inyectando… | |
| Pendiente de análisis | Alta (7.5) | 1.2% | 💥 PoC | Apache CamelAIInfinispanAI | 22/4/2026 | 23/9/2026 | A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over… |