Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

120 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)4.7%—HtmlunitDebian LinuxCanonical Ubuntu LinuxApache Camel11/2/202017/6/2026
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper…
ModificadaAlta (7.5)9.8%—Apache CamelOracle Enterprise Data QualityOracle Enterprise Manager Base PlatformOracle Flexcube Private Banking+128/5/201917/6/2026
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
ModificadaAlta (7.5)8.5%—Apache Camel30/4/201917/6/2026
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
ModificadaMedia (5.3)9.6%💥 PoCApache Camel17/9/201817/6/2026
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
ModificadaCrítica (9.8)5.4%—Apache Camel31/7/201817/6/2026
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
ModificadaAlta (7.5)1.5%—Decamelize Project Decamelize4/6/201817/6/2026
Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to evaluate a string and takes unescaped separator values, which can be used to create a denial of service attack.
ModificadaCrítica (9.8)7.2%—Apache Camel15/11/201717/6/2026
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
ModificadaCrítica (9.8)7.2%—Apache Camel15/11/201717/6/2026
The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
ModificadaCrítica (9.8)11%—Apache Camel28/3/201717/6/2026
Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
ModificadaAlta (7.4)5.9%—Apache Camel16/3/201717/6/2026
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
ModificadaCrítica (9.8)6.3%—Apache Camel7/3/201717/6/2026
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
ModificadaAlta (8.1)6.4%—Apache Camel15/4/201617/6/2026
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
ModificadaCrítica (9.8)7.1%—Apache Camel3/2/201617/6/2026
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
ModificadaMedia (5)7.1%—Apache Camel3/6/201517/6/2026
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.
ModificadaMedia (5)7.5%—Apache Camel3/6/201517/6/2026
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.
ModificadaAlta (7.5)7.5%—Apache Camel21/3/201417/6/2026
The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.
ModificadaAlta (7.5)27%—Apache Camel21/3/201417/6/2026
The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
ModificadaMedia (6.8)8.5%—Apache Camel4/10/201316/6/2026
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
ModificadaAlta (7.5)1.3%💥 ExploitJoomla COM Camelcitydb29/10/201116/6/2026
SQL injection vulnerability in the CamelcityDB (com_camelcitydb2) component 2.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
ModificadaMedia (5)2.6%💥 ExploitMythic Entertainment Dark AGE OF Camelot23/3/200416/6/2026
Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.
Orbitaley — Vulnerabilidades