Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
3901 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.5% | — | Apache Shardingsphere | 19/7/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a special YAML configuration file. The attacker needs to have permission to modify the ShardingSphere Agent YAML configuration file on the target machine, and the target… | |
| Analizada | Crítica (9.8) | 1.3% | — | Apache Eventmesh-connector-rabbitmq | 17/7/2023 | 17/6/2026 | CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. Users can use the code under the master branch in project… | |
| Modificada | Alta (8.8) | 1.6% | — | Apache-airflow-providers-apache-hive | 13/7/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon. This issue affects Apache Airflow Apache Hive Provider: before 6.1.2. It is recommended updating provider version to… | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Rocketmq | 12/7/2023 | 17/6/2026 | The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration… | |
| Modificada | Media (6.5) | 0.82% | — | Apache Pulsar | 12/7/2023 | 17/6/2026 | Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Any authenticated user can retrieve a source's configuration or a sink's configuration without authorization. Many sources and sinks contain credentials in the… | |
| Modificada | Media (6.5) | 1.6% | — | Apache Airflow | 12/7/2023 | 17/6/2026 | Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected | |
| Modificada | Media (6.5) | 1.0% | — | Apache Airflow | 12/7/2023 | 17/6/2026 | Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected | |
| Modificada | Media (6.5) | 1.0% | — | Apache Pulsar | 12/7/2023 | 17/6/2026 | Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authentication data expires if the client connected through the Pulsar Proxy when the broker is configured with authenticateOriginalAuthData=false or if a client connects… | |
| Modificada | Alta (8.8) | 1.0% | — | Apache Pulsar | 12/7/2023 | 17/6/2026 | Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. When a client connects to the Pulsar Function Worker via the Pulsar Proxy where the Pulsar Proxy uses mTLS authentication to authenticate with the Pulsar Function Worker, the… | |
| Modificada | Alta (8.1) | 0.82% | — | Apache Pulsar | 12/7/2023 | 17/6/2026 | Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP header to produce a message to any topic using the broker's admin role. This issue affects Apache Pulsar Brokers: from 2.9.0 through 2.9.5, from 2.10.0 before 2.10.4,… | |
| Modificada | Media (6.5) | 1.4% | — | Apache Airflow | 12/7/2023 | 17/6/2026 | Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_id parameter. This vulnerability is considered low since it requires an authenticated user to exploit it. It is recommended to upgrade to a version that is not affected | |
| Modificada | Media (6.5) | 1.8% | — | Apache Airflow | 12/7/2023 | 17/6/2026 | Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intended directory structure by manipulating the run_id parameter. This vulnerability is considered low since it requires an authenticated user to exploit it. It is recommended… | |
| Modificada | Media (6.5) | 1.2% | — | Apache Airflow | 12/7/2023 | 17/6/2026 | Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection resources specifically updating the connection to exploit it.… | |
| Modificada | Alta (8.8) | 1.2% | — | Apache Ambari | 12/7/2023 | 17/6/2026 | SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7. | |
| Modificada | Alta (8.8) | 1.2% | — | Apache Ambari | 12/7/2023 | 17/6/2026 | SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7. | |
| Modificada | Alta (8.8) | 1.5% | — | Apache Jena | 12/7/2023 | 17/6/2026 | There is insufficient restrictions of called script functions in Apache Jena versions 4.8.0 and earlier. It allows a remote user to execute javascript via a SPARQL query. This issue affects Apache Jena: from 3.7.0 through 4.8.0. | |
| Modificada | Media (4.3) | 1.3% | 💥 PoC | Apache Sshd | 10/7/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths… | |
| Modificada | Baja (3.3) | 0.43% | — | Apache Camel | 10/7/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X through <= 4.0.0-M3. Users should upgrade to 3.14.9, 3.18.8, 3.20.6 or… | |
| Modificada | Media (5.3) | 1.4% | — | Apache Johnzon | 7/7/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input that uses large numbers (numbers such as 1e20000000) that Apache Johnzon will deserialize into BigDecimal and maybe use numbers too large which may result in a slow conversion… | |
| Modificada | Media (5.3) | 1.5% | — | Apache Any23 | 5/7/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage. | |
| Modificada | Crítica (9.8) | 2.8% | — | Apache-airflow-providers-apache-hive | 3/7/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check to RCE via principal parameter. For this to be exploited it requires access to… | |
| Modificada | Alta (8.8) | 1.5% | — | Apache-airflow-providers-jdbc | 29/6/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement RCE attacks via different type JDBC drivers, obtain airflow server permission. This issue affects… | |
| Modificada | Media (4.3) | 1.3% | — | Apache-airflow-providers-microsoft-mssqlApache-airflow-providers-odbc | 27/6/2023 | 17/6/2026 | Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Apache Airflow MSSQL Provider.This vulnerability is considered low since it requires DAG code to use `get_sqlalchemy_connection` and someone with access to connection resources specifically updating… | |
| Modificada | Alta (7.8) | 0.76% | — | Apache-airflow-providers-odbc | 27/6/2023 | 17/6/2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foundation Apache Airflow ODBC Provider. In OdbcHook, A privilege escalation vulnerability exists in a system due to controllable ODBC driver parameters that allow the loading of arbitrary dynamic-link… | |
| Modificada | Alta (8.8) | 1.1% | — | Apache Streampipes | 23/6/2023 | 17/6/2026 | A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by upgrading to StreamPipes 0.92.0. |