Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2844▲ 206 respecto a la semana anterior
Críticas / altas1323▼ 110 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
3905 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Apache Inlong | 22/5/2023 | 17/6/2026 | Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. the user in InLong could cancel an application that doesn't belongs to it. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick… | |
| Modificada | Crítica (9.8) | 1.3% | — | Apache Inlong | 22/5/2023 | 17/6/2026 | Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. When the attacker has access to a valid (but unprivileged) account, the exploit can be executed using Burp Suite by sending a login request and following it with a… | |
| Modificada | Alta (7.5) | 1.2% | — | Apache Inlong | 22/5/2023 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can bind any cluster, even if he is not the cluster owner. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick [1] to… | |
| Modificada | Alta (7.5) | 1.2% | — | Apache Inlong | 22/5/2023 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can delete others' subscriptions, even if they are not the owner of the deleted subscription. Users are advised to upgrade to Apache… | |
| Modificada | Alta (7.5) | 1.2% | — | Apache Inlong | 22/5/2023 | 17/6/2026 | Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick [1] to solve it. [1]… | |
| Modificada | Alta (7.5) | 1.2% | — | Apache Inlong | 22/5/2023 | 17/6/2026 | Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers would bypass the 'autoDeserialize' option filtering by adding blanks. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick… | |
| Modificada | Alta (7.5) | 48% | — | Apache TomcatDebian LinuxNetapp 7-mode Transition Tool | 22/5/2023 | 17/6/2026 | The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly… | |
| Modificada | Crítica (9.8) | 2.2% | — | Apache Sling Commons Json | 15/5/2023 | 17/6/2026 | Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are encouraged to consider the Apache Sling… | |
| Modificada | Alta (7.2) | 1.5% | — | Apache Openmeetings | 12/5/2023 | 17/6/2026 | An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0 | |
| Modificada | Alta (8.1) | 1.1% | — | Apache Openmeetings | 12/5/2023 | 17/6/2026 | An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0 | |
| Modificada | Media (5.3) | 1.2% | — | Apache Openmeetings | 12/5/2023 | 17/6/2026 | Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0 | |
| Modificada | Crítica (9.8) | 2.3% | — | Apache Airflow | 8/5/2023 | 17/6/2026 | Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0. | |
| Modificada | Media (5.4) | 2.0% | — | Apache Airflow | 8/5/2023 | 17/6/2026 | Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0. | |
| Modificada | Crítica (9.8) | 1.5% | — | Apache Brpc | 8/5/2023 | 17/6/2026 | Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker that can influence the ServerOptions pid_file parameter with which the bRPC server is started can execute arbitrary code with the permissions of the bRPC process. Solution:… | |
| Modificada | Alta (8.8) | 1.6% | — | Apache Log4cxx | 8/5/2023 | 17/6/2026 | SQL injection in Log4cxx when using the ODBC appender to send log messages to a database. No fields sent to the database were properly escaped for SQL injection. This has been the case since at least version 0.9.0(released 2003-08-06) Note that Log4cxx is a C++ framework, so only C++ applications are affected. Before… | |
| Modificada | Alta (8.8) | 1.1% | — | Apache Ranger | 5/5/2023 | 17/6/2026 | Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0. | |
| Modificada | Alta (8.1) | 0.92% | — | Apache Ranger | 5/5/2023 | 17/6/2026 | An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0.… | |
| Modificada | Media (5.3) | 1.4% | — | Apache CouchdbIBM Cloudant | 2/5/2023 | 17/6/2026 | This doesn't affect map/reduce or search (Dreyfus) index functions. Users are recommended to upgrade to a version that is no longer affected by this issue (Apache CouchDB 3.3.2 or 3.2.3). Workaround: Avoid using design documents from untrusted sources which may attempt to cache or store data in the Javascript… | |
| Modificada | Alta (8.8) | 76% | — | Apache Spark | 2/5/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow… | |
| Modificada | Crítica (9.1) | 1.5% | — | Apache Streampark | 1/5/2023 | 17/6/2026 | Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, This will allow malicious attackers to send any username to… | |
| Modificada | Crítica (9.8) | 1.3% | — | Apache Streampark | 1/5/2023 | 17/6/2026 | Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later | |
| Modificada | Media (5.4) | 1.1% | — | Apache Streampark | 1/5/2023 | 17/6/2026 | Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize user input, it's possible to modify LDAP statements through techniques similar to… | |
| Modificada | Media (5.4) | 1.3% | — | Apache Jena | 25/4/2023 | 17/6/2026 | There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query. | |
| Modificada | Media (6.5) | 2.1% | — | Apache Superset | 24/4/2023 | 17/6/2026 | An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Apache Superset | 24/4/2023 | 17/6/2026 | Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have… |