Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
3889 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 0.70% | — | Apache Httpclient | 22/4/2026 | 9/9/2026 | Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue. | |
| Analizada | Media (5.3) | 0.89% | — | Apache Kafka | 20/4/2026 | 17/6/2026 | Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the sensitive information will be exposed via the… | |
| Modificada | Crítica (9.1) | 0.93% | — | Apache Kafka | 20/4/2026 | 15/7/2026 | A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audience. An attacker can… | |
| Analizada | Media (5.3) | 0.66% | — | Apache Doris MCP Server | 20/4/2026 | 7/10/2026 | Las versiones de Apache Doris MCP Servidor anteriores a la 0.6.1 se ven afectadas por una vulnerabilidad de neutralización inadecuada en el manejo del contexto de consulta que puede permitir la ejecución de sentencias SQL no intencionadas y la elusión de la validación de consultas prevista y las restricciones de… | |
| Analizada | Media (5.4) | 0.36% | — | Apache-airflow-providers-keycloak | 18/4/2026 | 17/6/2026 | The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm could deliver a crafted callback URL to a victim's browser and cause… | |
| Analizada | Baja (3.7) | 0.66% | — | Apache Airflow | 18/4/2026 | 17/6/2026 | Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0… | |
| Analizada | Alta (7.5) | 0.72% | — | Apache Airflow | 18/4/2026 | 17/6/2026 | UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. | |
| Analizada | Alta (7.5) | 0.76% | — | Apache Airflow | 18/4/2026 | 17/6/2026 | In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. | |
| Analizada | Alta (8.8) | 1.0% | — | Apache Airflow | 18/4/2026 | 17/6/2026 | An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow execute code on worker. Users should review if any of their own DAGs have adopted this incorrect advice. | |
| Modificada | Alta (7.2) | 1.1% | — | Apache Airflow | 18/4/2026 | 17/6/2026 | Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.83% | — | Apache Airflow | 16/4/2026 | 17/6/2026 | JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue. | |
| Analizada | Media (6.5) | 0.55% | — | Apache Airflow | 15/4/2026 | 17/6/2026 | The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidentaly logged to logs, those values could be seen in the logs. Azure Service Bus used… | |
| Analizada | Alta (7.5) | 0.59% | — | Apache Skywalking | 15/4/2026 | 17/6/2026 | The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0. Users are recommended to upgrade to version 10.4.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.58% | — | Jdeguest Apache\ | 15/4/2026 | 17/6/2026 | Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts. The _make_salt and _make_salt_bcrypt methods will attept to load Crypt::URandom and then Bytes::Random::Secure to generate random bytes for the salt. If those modules are unavailable, it will simply return 16 bytes… | |
| Analizada | Alta (8.1) | 0.58% | — | Apache Airflow | 15/4/2026 | 7/10/2026 | El ejemplo example_xcom que se incluyó en la documentación de Airflow implementó un patrón inseguro de lectura de valores de xcom de una manera que podría ser explotada para permitir que un usuario de la interfaz de usuario (UI) que tuviera acceso para modificar XComs realizara la ejecución arbitraria de código en el… | |
| Analizada | Media (4.3) | 0.96% | — | Apache Pdfbox | 14/4/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. Users are recommended to update to version 2.0.37 or 3.0.8 once available.… | |
| Analizada | Media (5.3) | 0.36% | — | Apache Apisix | 14/4/2026 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.37% | — | Apache Apisix | 14/4/2026 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue. | |
| Analizada | Crítica (9.1) | 0.60% | 💥 PoC | Apache Apisix | 14/4/2026 | 17/6/2026 | Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue. | |
| Analizada | Alta (8.8) | 1.1% | — | Apache Airflow | 13/4/2026 | 17/6/2026 | Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which resolves this… | |
| Analizada | Alta (7.5) | 0.44% | — | Apache Airflow | 13/4/2026 | 7/10/2026 | Antes de Airflow 3.2.0, no estaba claro que las implementaciones seguras de Airflow requieren que el Gestor de Implementación tome las acciones apropiadas y preste atención a los detalles de seguridad y al modelo de seguridad de Airflow. Algunas suposiciones que el Gestor de Implementación podría hacer no eran lo… | |
| Analizada | Alta (7.1) | 0.54% | — | Apache Skywalking MCP | 13/4/2026 | 17/6/2026 | Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue. | |
| Analizada | Media (5.4) | 0.59% | — | Apache Storm | 13/4/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and grouping values directly into HTML via innerHTML in parseNode() and… | |
| Analizada | Alta (8.8) | 1.1% | — | Apache Storm | 13/4/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInputStream.readObject() without any class filtering or validation. An… | |
| Analizada | Media (6.3) | 0.98% | — | Apache Log4cxx | 10/4/2026 | 17/6/2026 | Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in log messages, NDC, and MDC property keys and values, producing invalid XML… |