Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

142 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.45%—Sevenspark Bellows Accordion Menu30/10/202317/6/2026
The Bellows Accordion Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above…
ModificadaMedia (5.3)0.46%—Palmspark WP User Control13/9/202317/6/2026
The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.5.3. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (in the WP User Control Widget). The function changes the…
ModificadaCrítica (9.8)1.0%💥 PoCTrispark NovuseduTrispark VEO Transportation29/8/20239/7/2026
TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the "Student Busing Information" search queries.
ModificadaAlta (8.8)1.9%—Apache Airflow Spark Provider28/8/202317/6/2026
Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider. When the Apache Spark provider is installed on an Airflow deployment, an Airflow user that is authorized to configure Spark hooks can effectively run…
ModificadaAlta (7.5)2.1%—Apache-airflow-providers-apache-spark17/8/202317/6/2026
Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server. It is recommended to upgrade to a version that is not affected.
ModificadaCrítica (9.8)65%💥 ExploitColorlib ActivelloColorlib BonkersColorlib IlldyColorlib Newspaper X+127/6/202317/6/2026
The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <=…
ModificadaMedia (4.8)0.39%—Messagebird Sparkpost15/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SparkPost plugin <= 3.2.5 versions.
ModificadaAlta (8.8)76%—Apache Spark2/5/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow…
ModificadaCrítica (9.8)2.2%—Dawnsparks-node-tesseract Project Dawnsparks-node-tesseractHuedawn-tesseract Project Huedawn-tesseract24/4/202317/6/2026
huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
ModificadaCrítica (9.9)1.1%—Apache Spark17/4/202317/6/2026
In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application can execute code with the privileges of the submitting user, however, by providing malicious configuration-related classes on the classpath. This affects architectures…
ModificadaAlta (7.5)2.2%—Apache-airflow-providers-apache-spark7/4/202317/6/2026
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider: before 4.0.1.
ModificadaMedia (5.9)0.91%—DJI Spark Firmware27/3/202317/6/2026
DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To accomplish this, the attacker would first need to connect to the device's internal Wi-Fi network (e.g., by guessing the password). Then, the attacker would need to send many DHCP request…
ModificadaMedia (4.3)0.58%—Jenkins Cisco Spark26/1/202317/6/2026
A missing permission check in Jenkins Cisco Spark Notifier Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
ModificadaMedia (5.4)0.47%—Sevenspark Shiftnav23/1/202317/6/2026
The ShiftNav WordPress plugin before 1.7.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaMedia (5.5)1.4%—Apache AirflowApache-airflow-providers-apache-spark22/11/202217/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG files. This issue affects Spark Provider versions prior to…
ModificadaMedia (5.4)1.6%—Apache Spark1/11/202217/6/2026
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.
ModificadaAlta (7.8)0.37%—Uniwill Sparkio.sys5/8/202217/6/2026
The Uniwill SparkIO.sys driver 1.0 is vulnerable to a stack-based buffer overflow via IOCTL 0x40002008.
AnalizadaAlta (8.8)93%⚠ Explotación activa💥 ExploitApache Spark18/7/202217/6/2026
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation…
ModificadaMedia (4.3)0.59%—Jenkins Cisco Spark30/6/202217/6/2026
Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
ModificadaAlta (7.8)1.3%—Sparklabs Viscosity30/6/202217/6/2026
A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to…
ModificadaAlta (7.5)1.8%—Apache SparkOracle Financial Services Crime AND Compliance Management Studio10/3/202217/6/2026
Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to…
ModificadaMedia (6.1)1.0%—Fire.ly Spark14/5/202117/6/2026
Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted files to be delivered to clients such that they are rendered directly in a victim's web browser.
ModificadaAlta (8.8)1.4%—Jquery-sparkle Project Jquery-sparkle23/4/202117/6/2026
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.prototype.
ModificadaMedia (5.3)78%💥 PoCEclipse JettyApache NifiApache SparkNetapp E-series Santricity OS Controller+1226/2/202117/6/2026
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values,…
ModificadaCrítica (9.8)4.3%—Sparkdevnetwork Rock RMS7/1/202117/6/2026
Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklist that can be bypassed by adding multiple spaces and periods after the file name. This could allow an attacker to upload ASPX code and gain…
Orbitaley — Vulnerabilidades