Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
3901 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.9% | — | Apache Airflow Spark Provider | 28/8/2023 | 17/6/2026 | Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider. When the Apache Spark provider is installed on an Airflow deployment, an Airflow user that is authorized to configure Spark hooks can effectively run… | |
| Modificada | Alta (8.8) | 1.7% | — | Apache Airflow Sqoop Provider | 28/8/2023 | 17/6/2026 | Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, which makes it possible to implement RCE attacks via ‘sqoop import --connect’, obtain airflow server permissions, etc. The attacker needs to be logged in and have… | |
| Modificada | Media (6.1) | 6.0% | 💥 PoC | Apache TomcatDebian Linux | 25/8/2023 | 17/6/2026 | Vulnerabilidad de redirección de URL a sitio no fiable ('Open Redirect') en la función de autenticación FORM de Apache Tomcat. Este problema afecta a Apache Tomcat: de 11.0.0-M1 a 11.0.0-M10, de 10.1.0-M1 a 10.0.12, de 9.0.0-M1 a 9.0.79 y de 8.5.0 a 8.5.92. La vulnerabilidad se limita a la aplicación web ROOT (por… | |
| Modificada | Alta (7.8) | 2.1% | 💥 PoC | Vmware Spring FOR Apache Kafka | 24/8/2023 | 17/6/2026 | In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an… | |
| Modificada | Alta (8) | 1.8% | — | Apache Airflow | 23/8/2023 | 17/6/2026 | La vulnerabilidad de fijación de sesión permitía al usuario autenticado seguir accediendo al servidor web de Airflow incluso después de que el administrador hubiera restablecido la contraseña del usuario, hasta la expiración de la sesión del usuario. Aparte de limpiar manualmente la base de datos de sesiones (para el… | |
| Modificada | Media (5.9) | 0.80% | — | Apache AirflowApache-airflow-providers-imapApache-airflow-providers-smtp | 23/8/2023 | 17/6/2026 | Apache Airflow SMTP Provider antes de 1.3.0, Apache Airflow IMAP Provider antes de 3.3.0, y Apache Airflow antes de 2.7.0 están afectados por la vulnerabilidad Validation of OpenSSL Certificate. El contexto SSL por defecto con la librería SSL no comprobaba el certificado X.509 de un servidor. En su lugar, el código… | |
| Modificada | Alta (8.1) | 2.0% | — | Apache Airflow | 23/8/2023 | 17/6/2026 | Apache Airflow, en versiones anteriores a la 2.7.0, contiene una vulnerabilidad de seguridad que puede ser explotada por un usuario autenticado que posea privilegios de edición de conexión. Esta vulnerabilidad permite al usuario acceder a la información de conexión y explotar la función de conexión de prueba enviando… | |
| Modificada | Media (4.4) | 0.88% | — | Apache XML Graphics BatikDebian Linux | 22/8/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL. | |
| Modificada | Alta (7.1) | 0.92% | — | Apache XML Graphics BatikDebian Linux | 22/8/2023 | 8/10/2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure.… | |
| Modificada | Alta (8.2) | 2.0% | — | Apache IVY | 21/8/2023 | 17/6/2026 | Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven… | |
| Modificada | Media (6.5) | 2.1% | 💥 PoC | Apache Nifi | 18/8/2023 | 17/6/2026 | Apache NiFi 1.21.0 hasta 1.23.0 soportan accesos JDBC y JNDI JMS en varios procesadores y servicios de controlador con validación de URL de conexión que no proporciona suficiente protección contra entradas manipuladas. Un usuario autenticado y autorizado puede eludir la validación de URL de conexión utilizando un… | |
| Modificada | Alta (7.5) | 2.1% | — | Apache-airflow-providers-apache-spark | 17/8/2023 | 17/6/2026 | Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server. It is recommended to upgrade to a version that is not affected. | |
| Modificada | Alta (7.5) | 2.3% | — | Apache-airflow-providers-apache-drill | 11/8/2023 | 17/6/2026 | Vulnerabilidad de validación de entrada inadecuada en Apache Airflow Drill Provider de Apache Software Foundation. Apache Airflow Drill Provider está afectado por una vulnerabilidad que permite a un atacante pasar parámetros maliciosos al establecer una conexión con DrillHook dando la oportunidad de leer archivos en… | |
| Modificada | Crítica (9.1) | 1.6% | — | Apache Traffic Server | 9/8/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1. | |
| Modificada | Alta (7.5) | 2.0% | — | Apache Traffic Server | 9/8/2023 | 17/6/2026 | Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1. | |
| Modificada | Media (5.4) | 1.2% | — | Apache Roller | 6/8/2023 | 17/6/2026 | Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Roller configured for untrusted users, then you need to do nothing because… | |
| Modificada | Alta (8.8) | 2.6% | — | Apache Airflow | 5/8/2023 | 17/6/2026 | Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It allows to execute code in the webserver context as well as… | |
| Modificada | Alta (8.8) | 1.9% | 💥 PoC | Apache Nifi | 29/7/2023 | 17/6/2026 | Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution introduces a new Required Permission for referencing remote… | |
| Modificada | Crítica (9.8) | 2.0% | — | Apache Helix | 26/7/2023 | 17/6/2026 | An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can likely lead to remote code execution. The code can be run in Helix REST start… | |
| Modificada | Media (6.1) | 2.2% | — | Apache Felix Health Check Webconsole Plugin | 25/7/2023 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. Upgrade to Apache Felix Healthcheck Webconsole Plugin… | |
| Modificada | Crítica (9.8) | 3.2% | — | Apache Jackrabbit | 25/7/2023 | 17/6/2026 | Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that can be used for remote code execution… | |
| Modificada | Crítica (9.8) | 1.6% | — | Apache Inlong | 25/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. In the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query… | |
| Modificada | Alta (7.5) | 1.7% | — | Apache Inlong | 25/7/2023 | 17/6/2026 | Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick… | |
| Modificada | Media (6.5) | 1.3% | — | Apache Inlong | 25/7/2023 | 17/6/2026 | Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences. Users are advised to upgrade to Apache InLong's… | |
| Modificada | Crítica (9.8) | 2.1% | 💥 PoC | Apache Shiro | 24/7/2023 | 17/6/2026 | Apache Shiro, antes de 1.12.0 o 2.0.0-alpha-3, puede ser susceptible a un ataque de Path Traversal que resulta en una omisión de autenticación cuando se usa junto con API u otros marcos web que enrutan solicitudes basadas en solicitudes no normalizadas. Mitigación: actualización a Apache Shiro 1.12.0+ o 2.0.0-alpha-3+ |