Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2757▲ 47 respecto a la semana anterior
Críticas / altas1482▲ 372 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

942 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.3)0.85%—Opentelemetry-javaAIOpentelemetry-apiAIOpentelemetry-extension-trace-propagatorsAI28/5/202610/9/2026
opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized…
AplazadaBaja (2)0.41%—Linlinjava LitemallAI18/5/202617/6/2026
A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of the component Database Setting Handler. The manipulation of the argument db/password leads to…
AplazadaBaja (2)0.33%—Linlinjava LitemallAI18/5/202617/6/2026
A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admin Endpoint. Executing a manipulation can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Multiple…
AplazadaMedia (5.5)0.41%—Linlinjava LitemallAI18/5/202617/6/2026
A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxGoodsController.java of the component Front-end WeChat API. Performing a manipulation results in sql injection. Remote exploitation of the…
AplazadaAlta (7)0.84%—Microsoft Kiota-javaAIMicrosoft KiotaAI14/5/202617/6/2026
The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authorization, and all…
AplazadaAlta (7.5)0.42%—Yubico Webauthn-server-coreAIYubico Java-webauthn-serverAI14/5/202617/6/2026
Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.
ModificadaCrítica (9.1)0.50%—Microsoft Azure SDK FOR Java12/5/202617/6/2026
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity…
Pendiente de análisisAlta (8.6)0.55%—Eclipse Basyx Java Server SDKAI5/5/202624/7/2026
In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validate the destination URI of delegated requests. An unauthenticated remote attacker can exploit this design flaw to force the BaSyx server to execute blind HTTP POST requests to arbitrary internal or…
Pendiente de análisisCrítica (10)1.5%—Eclipse Basyx Java Server SDKAI5/5/202617/6/2026
In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a maliciously crafted fileName parameter during a file upload operation, an attacker can bypass…
AplazadaBaja (2)0.38%—Crmeb JavaAI3/5/202617/6/2026
A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/impl/UploadServiceImpl.java of the component Admin Upload. Performing a manipulation of the argument model results in unrestricted upload. Remote…
Pendiente de análisisMedia (5.3)0.36%—Langsmith Python SDKAIMatrix Javascript SDKAI23/4/202617/6/2026
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces…
AnalizadaAlta (7.5)0.41%—Oracle Java Virtual Machine21/4/202617/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.30 and 21.3-21.21. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in…
Pendiente de análisisAlta (8.9)0.96%—Bouncycastle Bc-javaAI15/4/202618/9/2026
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Pendiente de análisisMedia (6.3)0.69%—Legion OF THE Bouncy Castle INC Bcpix-ltsAIBouncycastle Bc-javaAIBouncycastle Bcpkix-fipsAI15/4/202618/9/2026
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated…
Pendiente de análisisAlta (8.7)0.88%—Bouncycastle Bc-javaAI15/4/202618/9/2026
Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java. This issue…
Pendiente de análisisMedia (5.5)0.53%—Bouncycastle Bc-javaAI15/4/202618/9/2026
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1,…
Pendiente de análisisCrítica (9.3)0.32%—Bouncycastle Bc-javaAI15/4/202630/9/2026
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
AnalizadaMedia (6.1)0.29%—SAP Netweaver Application Server Java14/4/202617/6/2026
Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If a victim accesses the affected functionality, that…
AplazadaMedia (5.5)0.50%—Nocobase Plugin-workflow-javascriptAI13/4/202617/6/2026
A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a manipulation results in sandbox issue. The attack can be initiated remotely. The…
AplazadaMedia (5.5)2.1%—Idachev Mcp-javadcAI8/4/202624/7/2026
A vulnerability was identified in idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP Interface. Such manipulation of the argument jarFilePath leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project…
AnalizadaAlta (7.6)0.20%—Lfprojects MCP Java SDK7/4/202624/7/2026
MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent.…
ModificadaMedia (6.1)0.31%—Lfprojects MCP Java SDK31/3/202624/7/2026
MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 0.83.0, 1.0.1, and 1.1.1.
AnalizadaCrítica (9.3)0.67%—Varaneckas JAD Java Decompiler28/3/202617/6/2026
JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boundaries. Attackers can craft malicious input passed to the jad command to overflow the stack and execute a…
AnalizadaCrítica (9.3)0.67%—Varaneckas JAD Java Decompiler28/3/202617/6/2026
JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 8150 bytes to overflow the stack, overwrite return addresses, and execute…
AnalizadaCrítica (9.3)0.99%—Datadog Dd-trace-java27/3/202617/6/2026
dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port…