Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

104 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Apache Thrift27/7/202628/7/2026
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
AnalizadaAlta (7.3)0.38%—Apache Thrift5/5/202617/6/2026
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0.…
ModificadaMedia (5.3)1.2%—Apache Thrift5/5/202621/7/2026
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
ModificadaAlta (7.3)0.81%—Apache Thrift5/5/20269/9/2026
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
AnalizadaAlta (8.7)0.73%—Apache Thrift28/4/202617/6/2026
Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
ModificadaMedia (6.5)0.90%—Apache Thrift28/4/20269/9/2026
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
ModificadaMedia (5.3)1.1%—Apache Thrift28/4/20269/9/2026
Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
ModificadaAlta (7.3)1.3%—Apache Thrift28/4/20269/9/2026
Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
ModificadaAlta (8.2)1.2%—Apache Thrift28/4/20269/9/2026
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
ModificadaAlta (7.5)1.4%—Apache Thrift28/4/20269/9/2026
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
ModificadaAlta (7.5)0.71%—Apache Thrift28/4/20267/10/2026
Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but…
AplazadaMedia (5.3)0.35%—Facebook ThriftAI27/9/202417/6/2026
A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other undesirable effects. This issue affects Facebook Thrift from v2024.09.09.00 until v2024.09.23.00.
AplazadaAlta (7.5)0.48%—Facebook ThriftAI27/9/202417/6/2026
A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2024.09.09.00.
ModificadaCrítica (9.8)1.7%—Facebook Thrift14/4/202117/6/2026
An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2021.02.22.00.
ModificadaAlta (7.5)6.8%—Apache HiveApache ThriftOracle Communications Cloud Native Core Network Slice Selection FunctionOracle Communications Cloud Native Core Policy12/2/202117/6/2026
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
ModificadaAlta (7.5)1.6%—Facebook Thrift18/3/202017/6/2026
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to…
ModificadaAlta (7.5)2.1%—Facebook Thrift10/3/202017/6/2026
C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to…
ModificadaAlta (7.5)2.3%—Facebook Thrift10/3/202017/6/2026
Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to…
ModificadaAlta (7.5)6.4%—Apache ThriftRedhat Jboss Enterprise Application PlatformOracle Communications Cloud Native Core Network Slice Selection Function29/10/201917/6/2026
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
ModificadaAlta (7.5)9.2%—Apache ThriftRedhat Jboss Enterprise Application PlatformOracle Communications Cloud Native Core Network Slice Selection Function29/10/201917/6/2026
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.
ModificadaAlta (7.5)2.8%—Facebook Thrift6/5/201917/6/2026
Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects…
ModificadaAlta (7.5)2.0%—Facebook Thrift6/5/201917/6/2026
Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to…
ModificadaAlta (7.5)2.0%—Facebook Thrift6/5/201917/6/2026
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to…
ModificadaAlta (7.5)2.0%—Facebook Thrift6/5/201917/6/2026
Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to…
ModificadaAlta (7.5)2.0%—Facebook Thrift6/5/201917/6/2026
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior…
Orbitaley — Vulnerabilidades