Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.72% | — | Jenkins Rabbitmq Consumer | 26/1/2023 | 17/6/2026 | A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified AMQP(S) URL using attacker-specified username and password. | |
| Modificada | Alta (8.8) | 0.52% | — | Jenkins Rabbitmq Consumer | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers to connect to an attacker-specified AMQP(S) URL using attacker-specified username and password. | |
| Modificada | Alta (7.5) | 0.40% | — | Broadcom Rabbitmq ServerVmware Rabbitmq | 6/10/2022 | 17/6/2026 | RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and… | |
| Modificada | Media (4.8) | 1.4% | — | Vmware Rabbitmq | 28/6/2021 | 17/6/2026 | RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript… | |
| Modificada | Media (5.4) | 1.4% | — | Vmware Rabbitmq | 28/6/2021 | 17/6/2026 | RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `<script>` tag sanitization, potentially allowing for JavaScript code execution in the context of the… | |
| Modificada | Alta (7.5) | 1.4% | — | Vmware RabbitmqDebian Linux | 8/6/2021 | 17/6/2026 | RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugin enabled. | |
| Modificada | Alta (7.8) | 0.61% | — | Broadcom Rabbitmq Server | 18/5/2021 | 17/6/2026 | RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins. | |
| Modificada | Crítica (9.8) | 2.8% | — | Rabbitmq JMS Client | 12/3/2021 | 17/6/2026 | JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data. | |
| Modificada | Crítica (9.8) | 2.2% | — | Rabbitmq Docker Image | 17/12/2020 | 17/6/2026 | The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Media (6.7) | 0.45% | — | Broadcom Rabbitmq ServerPivotal Software Rabbitmq | 31/8/2020 | 17/6/2026 | RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and… | |
| Modificada | Crítica (9.8) | 3.3% | — | Rabbitmq-c Project Rabbitmq-cFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux | 1/12/2019 | 17/6/2026 | An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition… | |
| Modificada | Alta (7.5) | 4.4% | 💥 PoC | Broadcom Rabbitmq ServerPivotal Software RabbitmqFedoraproject FedoraRedhat Openstack+1 | 23/11/2019 | 17/6/2026 | Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a… | |
| Modificada | Media (4.8) | 0.80% | — | Broadcom Rabbitmq ServerVmware RabbitmqRedhat Openstack | 22/11/2019 | 17/6/2026 | Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative… | |
| Modificada | Media (4.8) | 1.2% | — | Pivotal Software RabbitmqRedhat OpenstackRedhat Openstack FOR IBM PowerDebian Linux+1 | 16/10/2019 | 17/6/2026 | Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote… | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Media (6.5) | 1.8% | — | Pivotal Software Rabbitmq | 10/12/2018 | 17/6/2026 | Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on any server in the… | |
| Analizada | Media (5.9) | 1.2% | — | Pivotal Software Spring Advanced Message Queuing ProtocolVmware Rabbitmq Java Client | 14/9/2018 | 17/6/2026 | Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit. | |
| Modificada | Media (6.1) | 1.9% | — | Broadcom Rabbitmq ServerPivotal Software RabbitmqDebian Linux | 13/6/2017 | 17/6/2026 | An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable… | |
| Modificada | Alta (7.8) | 0.37% | — | Broadcom Rabbitmq ServerPivotal Software RabbitmqDebian Linux | 13/6/2017 | 17/6/2026 | An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in… | |
| Modificada | Media (6.1) | 3.3% | — | Broadcom Rabbitmq ServerPivotal Software RabbitmqDebian Linux | 13/6/2017 | 17/6/2026 | An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable… | |
| Modificada | Crítica (9.8) | 1.4% | — | Broadcom Rabbitmq ServerPivotal Software Rabbitmq | 29/12/2016 | 17/6/2026 | An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password… | |
| Modificada | Media (6.5) | 3.5% | — | Oracle SolarisPivotal Software Rabbitmq | 9/12/2016 | 17/6/2026 | The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Pivotal Software Rabbitmq | 18/9/2016 | 17/6/2026 | The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line. | |
| Modificada | Baja (2.1) | 0.35% | — | Voxpupuli Rabbitmq | 3/2/2015 | 17/6/2026 | puppetlabs-rabbitmq 3.0 through 4.1 stores the RabbitMQ Erlang cookie value in the facts of a node, which allows local users to obtain sensitive information as demonstrated by using Facter. | |
| Modificada | Media (5) | 2.6% | — | Broadcom Rabbitmq Server | 27/1/2015 | 17/6/2026 | CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions. |