Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2834▲ 197 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
3905 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.5% | — | Apache-airflow-providers-jdbc | 29/6/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement RCE attacks via different type JDBC drivers, obtain airflow server permission. This issue affects… | |
| Modificada | Media (4.3) | 1.3% | — | Apache-airflow-providers-microsoft-mssqlApache-airflow-providers-odbc | 27/6/2023 | 17/6/2026 | Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Apache Airflow MSSQL Provider.This vulnerability is considered low since it requires DAG code to use `get_sqlalchemy_connection` and someone with access to connection resources specifically updating… | |
| Modificada | Alta (7.8) | 0.76% | — | Apache-airflow-providers-odbc | 27/6/2023 | 17/6/2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foundation Apache Airflow ODBC Provider. In OdbcHook, A privilege escalation vulnerability exists in a system due to controllable ODBC driver parameters that allow the loading of arbitrary dynamic-link… | |
| Modificada | Alta (8.8) | 1.1% | — | Apache Streampipes | 23/6/2023 | 17/6/2026 | A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by upgrading to StreamPipes 0.92.0. | |
| Modificada | Alta (7.5) | 1.1% | — | Apache Tomcat | 21/6/2023 | 17/6/2026 | A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the… | |
| Modificada | Crítica (9.8) | 1.4% | — | Apache Accumulo | 21/6/2023 | 17/6/2026 | Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 contains a defect in the user authentication process that may succeed when invalid credentials are provided. Users are advised to upgrade to 2.1.1. | |
| Modificada | Media (6.5) | 1.5% | — | Apache Airflow | 19/6/2023 | 17/6/2026 | In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerability is mitigated by the fact configuration is not shown in the UI by default (only if `[webserver] expose_config` is set to `non-sensitive-only`), and not all uncensored values are actually… | |
| Modificada | Alta (7.5) | 5.5% | — | Apache Struts | 14/6/2023 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Upgrade to Struts 2.5.31 or 6.1.2.1 or greater | |
| Modificada | Media (6.5) | 5.4% | — | Apache Struts | 14/6/2023 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Upgrade to Struts 2.5.31 or 6.1.2.1 or greater. | |
| Modificada | Alta (7.5) | 1.5% | — | Apache Traffic Server | 14/6/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0. 8.x users should upgrade to 8.1.7 or later versions 9.x users should upgrade to 9.2.1 or later versions | |
| Modificada | Alta (7.5) | 2.0% | — | Apache Traffic ServerDebian LinuxFedoraproject Fedora | 14/6/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through… | |
| Modificada | Alta (7.5) | 1.5% | — | Apache Traffic ServerDebian Linux | 14/6/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0. | |
| Modificada | Alta (8.8) | 62% | 💥 Exploit | Apache Nifi | 12/6/2023 | 17/6/2026 | The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are… | |
| Modificada | Media (6.5) | 2.4% | 💥 PoC | Apache Nifi | 12/6/2023 | 17/6/2026 | The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from a remote location. The resolution… | |
| Modificada | Alta (8.1) | 1.1% | — | Apache Guacamole | 7/6/2023 | 17/6/2026 | Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to execute arbitrary code with the privileges of the guacd process. | |
| Modificada | Alta (7.5) | 1.0% | — | Apache Guacamole | 7/6/2023 | 17/6/2026 | Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake, potentially allowing an attacker to inject Guacamole instructions during the handshake through specially-crafted data. | |
| Modificada | Alta (7.2) | 1.5% | — | Apache-airflow-providers-cncf-kubernetes | 30/5/2023 | 2/7/2026 | Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. Operators… | |
| Modificada | Alta (7.8) | 0.34% | — | Apache Cassandra | 30/5/2023 | 17/6/2026 | Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1. WORKAROUND The vulnerability requires nodetool/JMX access to be exploitable, disable… | |
| Modificada | Media (6.1) | 1.2% | 💥 PoC | Apache Jspwiki | 25/5/2023 | 17/6/2026 | A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.0 or later. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Apache Rocketmq | 24/5/2023 | 17/6/2026 | For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update… | |
| Modificada | Alta (7.5) | 1.3% | — | Apache Inlong | 22/5/2023 | 17/6/2026 | Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick… | |
| Modificada | Media (6.5) | 1.1% | — | Apache Inlong | 22/5/2023 | 17/6/2026 | Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see deleted users' data. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick… | |
| Modificada | Crítica (9.8) | 1.2% | — | Apache Inlong | 22/5/2023 | 17/6/2026 | Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0. When users change their password to a simple password (with any character or symbol), attackers can easily guess the user's password and access the account. Users are advised… | |
| Modificada | Crítica (9.1) | 1.4% | — | Apache Inlong | 22/5/2023 | 17/6/2026 | Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick… | |
| Modificada | Crítica (9.1) | 1.2% | — | Apache Inlong | 22/5/2023 | 17/6/2026 | Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. An old session can be used by an attacker even after the user has been deleted or the password has been changed. Users are advised to upgrade to Apache InLong's 1.7.0 or… |