Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.45% | — | Sevenspark Bellows Accordion Menu | 30/10/2023 | 17/6/2026 | The Bellows Accordion Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above… | |
| Modificada | Media (5.3) | 0.46% | — | Palmspark WP User Control | 13/9/2023 | 17/6/2026 | The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.5.3. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (in the WP User Control Widget). The function changes the… | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Trispark NovuseduTrispark VEO Transportation | 29/8/2023 | 9/7/2026 | TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the "Student Busing Information" search queries. | |
| Modificada | Alta (8.8) | 1.9% | — | Apache Airflow Spark Provider | 28/8/2023 | 17/6/2026 | Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider. When the Apache Spark provider is installed on an Airflow deployment, an Airflow user that is authorized to configure Spark hooks can effectively run… | |
| Modificada | Alta (7.5) | 2.1% | — | Apache-airflow-providers-apache-spark | 17/8/2023 | 17/6/2026 | Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server. It is recommended to upgrade to a version that is not affected. | |
| Modificada | Crítica (9.8) | 65% | 💥 Exploit | Colorlib ActivelloColorlib BonkersColorlib IlldyColorlib Newspaper X+12 | 7/6/2023 | 17/6/2026 | The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <=… | |
| Modificada | Media (4.8) | 0.39% | — | Messagebird Sparkpost | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SparkPost plugin <= 3.2.5 versions. | |
| Modificada | Alta (8.8) | 76% | — | Apache Spark | 2/5/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow… | |
| Modificada | Crítica (9.8) | 2.2% | — | Dawnsparks-node-tesseract Project Dawnsparks-node-tesseractHuedawn-tesseract Project Huedawn-tesseract | 24/4/2023 | 17/6/2026 | huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. | |
| Modificada | Crítica (9.9) | 1.1% | — | Apache Spark | 17/4/2023 | 17/6/2026 | In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application can execute code with the privileges of the submitting user, however, by providing malicious configuration-related classes on the classpath. This affects architectures… | |
| Modificada | Alta (7.5) | 2.2% | — | Apache-airflow-providers-apache-spark | 7/4/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider: before 4.0.1. | |
| Modificada | Media (5.9) | 0.91% | — | DJI Spark Firmware | 27/3/2023 | 17/6/2026 | DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To accomplish this, the attacker would first need to connect to the device's internal Wi-Fi network (e.g., by guessing the password). Then, the attacker would need to send many DHCP request… | |
| Modificada | Media (4.3) | 0.58% | — | Jenkins Cisco Spark | 26/1/2023 | 17/6/2026 | A missing permission check in Jenkins Cisco Spark Notifier Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (5.4) | 0.47% | — | Sevenspark Shiftnav | 23/1/2023 | 17/6/2026 | The ShiftNav WordPress plugin before 1.7.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Media (5.5) | 1.4% | — | Apache AirflowApache-airflow-providers-apache-spark | 22/11/2022 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG files. This issue affects Spark Provider versions prior to… | |
| Modificada | Media (5.4) | 1.6% | — | Apache Spark | 1/11/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI. | |
| Modificada | Alta (7.8) | 0.37% | — | Uniwill Sparkio.sys | 5/8/2022 | 17/6/2026 | The Uniwill SparkIO.sys driver 1.0 is vulnerable to a stack-based buffer overflow via IOCTL 0x40002008. | |
| Analizada | Alta (8.8) | 93% | ⚠ Explotación activa💥 Exploit | Apache Spark | 18/7/2022 | 17/6/2026 | The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation… | |
| Modificada | Media (4.3) | 0.59% | — | Jenkins Cisco Spark | 30/6/2022 | 17/6/2026 | Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Alta (7.8) | 1.3% | — | Sparklabs Viscosity | 30/6/2022 | 17/6/2026 | A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to… | |
| Modificada | Alta (7.5) | 1.8% | — | Apache SparkOracle Financial Services Crime AND Compliance Management Studio | 10/3/2022 | 17/6/2026 | Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to… | |
| Modificada | Media (6.1) | 1.0% | — | Fire.ly Spark | 14/5/2021 | 17/6/2026 | Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted files to be delivered to clients such that they are rendered directly in a victim's web browser. | |
| Modificada | Alta (8.8) | 1.4% | — | Jquery-sparkle Project Jquery-sparkle | 23/4/2021 | 17/6/2026 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.prototype. | |
| Modificada | Media (5.3) | 78% | 💥 PoC | Eclipse JettyApache NifiApache SparkNetapp E-series Santricity OS Controller+12 | 26/2/2021 | 17/6/2026 | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values,… | |
| Modificada | Crítica (9.8) | 4.3% | — | Sparkdevnetwork Rock RMS | 7/1/2021 | 17/6/2026 | Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklist that can be bypassed by adding multiple spaces and periods after the file name. This could allow an attacker to upload ASPX code and gain… |