Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2757▲ 47 respecto a la semana anterior
Críticas / altas1482▲ 372 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
942 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.85% | — | Opentelemetry-javaAIOpentelemetry-apiAIOpentelemetry-extension-trace-propagatorsAI | 28/5/2026 | 10/9/2026 | opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized… | |
| Aplazada | Baja (2) | 0.41% | — | Linlinjava LitemallAI | 18/5/2026 | 17/6/2026 | A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of the component Database Setting Handler. The manipulation of the argument db/password leads to… | |
| Aplazada | Baja (2) | 0.33% | — | Linlinjava LitemallAI | 18/5/2026 | 17/6/2026 | A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admin Endpoint. Executing a manipulation can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Multiple… | |
| Aplazada | Media (5.5) | 0.41% | — | Linlinjava LitemallAI | 18/5/2026 | 17/6/2026 | A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxGoodsController.java of the component Front-end WeChat API. Performing a manipulation results in sql injection. Remote exploitation of the… | |
| Aplazada | Alta (7) | 0.84% | — | Microsoft Kiota-javaAIMicrosoft KiotaAI | 14/5/2026 | 17/6/2026 | The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authorization, and all… | |
| Aplazada | Alta (7.5) | 0.42% | — | Yubico Webauthn-server-coreAIYubico Java-webauthn-serverAI | 14/5/2026 | 17/6/2026 | Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation. | |
| Modificada | Crítica (9.1) | 0.50% | — | Microsoft Azure SDK FOR Java | 12/5/2026 | 17/6/2026 | The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity… | |
| Pendiente de análisis | Alta (8.6) | 0.55% | — | Eclipse Basyx Java Server SDKAI | 5/5/2026 | 24/7/2026 | In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validate the destination URI of delegated requests. An unauthenticated remote attacker can exploit this design flaw to force the BaSyx server to execute blind HTTP POST requests to arbitrary internal or… | |
| Pendiente de análisis | Crítica (10) | 1.5% | — | Eclipse Basyx Java Server SDKAI | 5/5/2026 | 17/6/2026 | In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a maliciously crafted fileName parameter during a file upload operation, an attacker can bypass… | |
| Aplazada | Baja (2) | 0.38% | — | Crmeb JavaAI | 3/5/2026 | 17/6/2026 | A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/impl/UploadServiceImpl.java of the component Admin Upload. Performing a manipulation of the argument model results in unrestricted upload. Remote… | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | Langsmith Python SDKAIMatrix Javascript SDKAI | 23/4/2026 | 17/6/2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Java Virtual Machine | 21/4/2026 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.30 and 21.3-21.21. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in… | |
| Pendiente de análisis | Alta (8.9) | 0.96% | — | Bouncycastle Bc-javaAI | 15/4/2026 | 18/9/2026 | Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84. | |
| Pendiente de análisis | Media (6.3) | 0.69% | — | Legion OF THE Bouncy Castle INC Bcpix-ltsAIBouncycastle Bc-javaAIBouncycastle Bcpkix-fipsAI | 15/4/2026 | 18/9/2026 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated… | |
| Pendiente de análisis | Alta (8.7) | 0.88% | — | Bouncycastle Bc-javaAI | 15/4/2026 | 18/9/2026 | Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java. This issue… | |
| Pendiente de análisis | Media (5.5) | 0.53% | — | Bouncycastle Bc-javaAI | 15/4/2026 | 18/9/2026 | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1,… | |
| Pendiente de análisis | Crítica (9.3) | 0.32% | — | Bouncycastle Bc-javaAI | 15/4/2026 | 30/9/2026 | : Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84. | |
| Analizada | Media (6.1) | 0.29% | — | SAP Netweaver Application Server Java | 14/4/2026 | 17/6/2026 | Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If a victim accesses the affected functionality, that… | |
| Aplazada | Media (5.5) | 0.50% | — | Nocobase Plugin-workflow-javascriptAI | 13/4/2026 | 17/6/2026 | A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a manipulation results in sandbox issue. The attack can be initiated remotely. The… | |
| Aplazada | Media (5.5) | 2.1% | — | Idachev Mcp-javadcAI | 8/4/2026 | 24/7/2026 | A vulnerability was identified in idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP Interface. Such manipulation of the argument jarFilePath leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project… | |
| Analizada | Alta (7.6) | 0.20% | — | Lfprojects MCP Java SDK | 7/4/2026 | 24/7/2026 | MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent.… | |
| Modificada | Media (6.1) | 0.31% | — | Lfprojects MCP Java SDK | 31/3/2026 | 24/7/2026 | MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 0.83.0, 1.0.1, and 1.1.1. | |
| Analizada | Crítica (9.3) | 0.67% | — | Varaneckas JAD Java Decompiler | 28/3/2026 | 17/6/2026 | JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boundaries. Attackers can craft malicious input passed to the jad command to overflow the stack and execute a… | |
| Analizada | Crítica (9.3) | 0.67% | — | Varaneckas JAD Java Decompiler | 28/3/2026 | 17/6/2026 | JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 8150 bytes to overflow the stack, overwrite return addresses, and execute… | |
| Analizada | Crítica (9.3) | 0.99% | — | Datadog Dd-trace-java | 27/3/2026 | 17/6/2026 | dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port… |