Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
3872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.7) | 0.15% | — | Apache ApisixAI | 1/10/2026 | 1/10/2026 | Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause the unmasked header value to be written to the log sink under a certain response structure. This issue affects Apache APISIX: 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Apache CamelAI | 30/9/2026 | 2/10/2026 | In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary. | |
| Aplazada | Crítica (9.8) | 0.40% | — | Apache CamelAI | 30/9/2026 | 2/10/2026 | In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary. | |
| En análisis | Alta (7.5) | 0.29% | — | Apache Wss4jAI | 30/9/2026 | 30/9/2026 | An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before… | |
| Analizada | Media (4.8) | 0.51% | — | Apache Wss4j | 30/9/2026 | 2/10/2026 | Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could… | |
| En análisis | Alta (7.5) | 0.35% | — | Apache Wss4jAI | 30/9/2026 | 30/9/2026 | In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of… | |
| En análisis | Crítica (9.1) | 0.21% | — | Apache Wss4jAI | 30/9/2026 | 30/9/2026 | WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | |
| Analizada | Crítica (9.8) | 0.57% | — | Apache Wss4j | 30/9/2026 | 2/10/2026 | An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix… | |
| En análisis | Crítica (9.1) | 0.18% | — | Apache CXFAI | 30/9/2026 | 30/9/2026 | In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to… | |
| Analizada | Alta (7.5) | 0.55% | — | Apache Wss4j | 30/9/2026 | 2/10/2026 | Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a… | |
| Pendiente de análisis | Crítica (9.1) | 0.38% | — | Apache Mina SshdAI | 30/9/2026 | 30/9/2026 | Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the… | |
| Pendiente de análisis | Crítica (9.1) | 0.38% | — | Apache Mina SshdAI | 30/9/2026 | 30/9/2026 | A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and… | |
| Pendiente de análisis | Media (6.5) | 0.38% | — | Apache Mina SshdAI | 30/9/2026 | 30/9/2026 | Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH. Using a very small "block size" (for instance 256, which is the minimum)… | |
| Pendiente de análisis | Alta (7.5) | 0.43% | — | Apache Mina SshdAI | 30/9/2026 | 30/9/2026 | Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP. The SFTP client implementation, when… | |
| Pendiente de análisis | Media (6.5) | 0.33% | — | Apache Mina SshdAI | 30/9/2026 | 30/9/2026 | Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component sshd-scp of Apache MINA SSHD provides a Java implementation of SCP. The SCP command protocol is line-oriented with… | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | Apache Mina SshdAI | 30/9/2026 | 30/9/2026 | Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though class GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that… | |
| Pendiente de análisis | Alta (8.1) | 0.32% | — | Apache Mina SshdAI | 30/9/2026 | 30/9/2026 | Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods "publickey,publickey". Apache MINA SSHD… | |
| Pendiente de análisis | Crítica (9.1) | 0.51% | — | Apache Mina SshdAI | 30/9/2026 | 30/9/2026 | Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous… | |
| Pendiente de análisis | Alta (8.5) | 0.18% | — | Apache Plc4xAI | 30/9/2026 | 30/9/2026 | Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection address… | |
| Pendiente de análisis | Alta (8.7) | 0.33% | — | Apache Plc4xAI | 30/9/2026 | 30/9/2026 | Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application, causing a… | |
| Pendiente de análisis | Alta (8.7) | 0.40% | — | Apache Plc4xAI | 30/9/2026 | 30/9/2026 | Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service. In the OPC UA driver these… | |
| Pendiente de análisis | Crítica (9.2) | 0.13% | — | Apache Plc4xAI | 30/9/2026 | 30/9/2026 | Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by… | |
| Aplazada | Alta (8.1) | 0.28% | — | Apache PolarisAI | 29/9/2026 | 1/10/2026 | Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to… | |
| Aplazada | Media (4.3) | 0.23% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow belonging to that project through a sub-workflow task. The system does not properly verify whether the user has… | |
| Aplazada | Media (5.3) | 0.35% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafted request containing a percent-encoded path, a remote unauthenticated… |