Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▲ 220 respecto a la semana anterior
Críticas / altas1330▼ 101 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
3905 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Apache Dolphinscheduler | 20/4/2023 | 17/6/2026 | On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attacker could use a socket bytes attack without authentication. This issue has been fixed from version 3.1.2 onwards. For users who use version 3.0.0 to 3.1.1, you can turn off the python-gateway… | |
| Modificada | Media (4.3) | 0.78% | — | Apache Superset | 17/4/2023 | 17/6/2026 | An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1 | |
| Modificada | Media (6.5) | 0.96% | — | Apache Superset | 17/4/2023 | 17/6/2026 | A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery attacks and query internal resources on behalf of the server where Superset is deployed. This vulnerability exists in Apache Superset… | |
| Modificada | Crítica (9.8) | 1.4% | — | Apache Iotdb WEB Workbench | 17/4/2023 | 17/6/2026 | Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database. This problem is fixed from version 0.13.4 of iotdb-web-workbench onwards. | |
| Modificada | Crítica (9.9) | 1.1% | — | Apache Spark | 17/4/2023 | 17/6/2026 | In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application can execute code with the privileges of the submitting user, however, by providing malicious configuration-related classes on the classpath. This affects architectures… | |
| Modificada | Crítica (9.8) | 1.2% | — | Apache Iotdb | 17/4/2023 | 17/6/2026 | Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3. Attackers could login without authorization. This is fixed in 0.13.4. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Apache Ofbiz | 14/4/2023 | 17/6/2026 | Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07. | |
| Analizada | Crítica (9) | 1.1% | — | Apache Sling Engine | 13/4/2023 | 17/6/2026 | The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resource with specific content-type and control the include path… | |
| Modificada | Media (5.3) | 1.2% | — | Apache Inlong | 11/4/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.5.0. By manipulating the "orderType" parameter and the ordering of the returned content using an SQL injection attack, an… | |
| Modificada | Crítica (9.8) | 2.1% | — | Apache Linkis | 10/4/2023 | 17/6/2026 | In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserialization vulnerability, eventually leading to remote code execution. Versions of Apache Linkis <= 1.3.0 will be affected. We… | |
| Modificada | Crítica (9.8) | 2.1% | — | Apache Linkis | 10/4/2023 | 17/6/2026 | In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote code execution. Therefore, the parameters in the Mysql JDBC URL should be… | |
| Modificada | Crítica (9.1) | 0.81% | — | Apache Linkis | 10/4/2023 | 17/6/2026 | In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values. We recommend users upgrade the version of Linkis to version 1.3.2 And modify the default token… | |
| Modificada | Crítica (9.8) | 1.8% | — | Apache Linkis | 10/4/2023 | 17/6/2026 | In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2. | |
| Modificada | Crítica (9.8) | 2.0% | — | Apache Linkis | 10/4/2023 | 17/6/2026 | In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2. For versions <=1.3.1, we suggest turning on the file path check switch in linkis.properties… | |
| Modificada | Alta (7.5) | 2.2% | — | Apache-airflow-providers-apache-spark | 7/4/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider: before 4.0.1. | |
| Modificada | Alta (7.5) | 2.1% | — | Apache-airflow-providers-apache-drill | 7/4/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2. | |
| Modificada | Crítica (9.8) | 2.8% | — | Apache Airflow Hive Provider | 7/4/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0. | |
| Modificada | Alta (7.8) | 0.65% | 💥 PoC | Apache James | 3/4/2023 | 17/6/2026 | Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that version 3.7.4 onward will set up a JMX password automatically for… | |
| Modificada | Alta (8.8) | 2.9% | — | Apache Unstructured Information Management Architecture | 30/3/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA, an authenticated user that has the permissions to modify… | |
| Modificada | Media (5.4) | 1.2% | — | Apache Archiva | 29/3/2023 | 17/6/2026 | Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user. | |
| Modificada | Crítica (9.8) | 1.3% | — | Apache Openmeetings | 28/3/2023 | 17/6/2026 | Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room | |
| Modificada | Media (6.3) | 1.1% | — | Apache Fineract | 28/3/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract. Authorized users may be able to exploit this for limited impact on components. This issue affects apache fineract: from 1.4 through 1.8.2. | |
| Modificada | Media (4.3) | 1.3% | — | Apache Fineract | 28/3/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache Fineract. Authorized users may be able to change or add data in certain components. This issue affects Apache Fineract: from 1.4 through 1.8.2. | |
| Modificada | Alta (8.1) | 0.98% | — | Apache Fineract | 28/3/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain access to server and may be able to use server for any outbound traffic. This issue affects Apache Fineract: from 1.4 through 1.8.3. | |
| Modificada | Alta (8.8) | 1.5% | — | Apache Inlong | 27/3/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong, you could refer to [1] to know more about this vulnerability. This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's… |