Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
3880 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.44% | — | Apache Qpid Broker-j | 25/9/2026 | 5/10/2026 | Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version… | |
| Analizada | Alta (7.5) | 0.47% | — | Apache Qpid Broker-j | 25/9/2026 | 5/10/2026 | Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are… | |
| Pendiente de análisis | Media (6.5) | 0.37% | — | Apache Airflow Hashicorp ProviderAI | 24/9/2026 | 25/9/2026 | Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different… | |
| Pendiente de análisis | Alta (8.1) | 0.23% | — | Apache DolphinschedulerAI | 24/9/2026 | 24/9/2026 | A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are… | |
| Analizada | Alta (7.4) | 0.18% | — | Apache Tomcat Native | 23/9/2026 | 6/10/2026 | Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected. Users are… | |
| Analizada | Crítica (9.1) | 0.28% | — | Apache Tomcat Native | 23/9/2026 | 6/10/2026 | Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0… | |
| Analizada | Alta (7.5) | 0.40% | — | Apache Tomcat Native | 23/9/2026 | 6/10/2026 | Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are recommended to upgrade… | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Apache TomcatAI | 23/9/2026 | 23/9/2026 | Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the… | |
| Pendiente de análisis | Crítica (9.1) | 0.31% | — | Apache TomcatAI | 23/9/2026 | 23/9/2026 | Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through… | |
| Pendiente de análisis | Crítica (9.8) | 0.39% | — | Apache TomcatAI | 23/9/2026 | 23/9/2026 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60… | |
| Pendiente de análisis | Alta (7.5) | 0.32% | — | Apache TomcatAI | 23/9/2026 | 23/9/2026 | Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost time outs for asynchronous WebSocket writes. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1… | |
| Pendiente de análisis | Alta (7.3) | 0.26% | — | Apache TomcatAI | 23/9/2026 | 23/9/2026 | Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121. Users are recommended to upgrade to… | |
| Pendiente de análisis | Alta (7.5) | 0.38% | — | Apache TomcatAI | 23/9/2026 | 23/9/2026 | Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The… | |
| Pendiente de análisis | Alta (7.5) | 0.53% | — | Apache TomcatAI | 23/9/2026 | 23/9/2026 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomcat: from 11.0.0-M5 through 11.0.25, from 10.1.8 through 10.1.59, from 9.0.74 through 9.0.121. The following versions were EOL at the time the CVE was created… | |
| Pendiente de análisis | Alta (8.1) | 0.36% | — | Apache TomcatAI | 23/9/2026 | 30/9/2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an attacker to inject trailer fields into another HTTP/2 request. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.39 through… | |
| Pendiente de análisis | Baja (3.7) | 0.26% | — | Apache TomcatAI | 23/9/2026 | 23/9/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused by processing the transfer-encoding header for an HTTP/1.0 request may allow an attacker to cause one request from another user to fail when Tomcat is located behind a reverse proxy. This issue… | |
| Pendiente de análisis | Crítica (9.8) | 0.39% | — | Apache TomcatAI | 23/9/2026 | 30/9/2026 | Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time… | |
| Pendiente de análisis | Alta (7.3) | 0.24% | — | Apache TomcatAI | 23/9/2026 | 23/9/2026 | Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provider, the realm for the first web application to authenticate a request would be used for all web applications. This issue… | |
| Pendiente de análisis | Media (6.5) | 0.12% | — | Apache TomcatAI | 23/9/2026 | 30/9/2026 | Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0-M1 through 9.0.121. The following… | |
| Pendiente de análisis | Media (6.5) | 0.34% | — | Apache DorisAI | 23/9/2026 | 23/9/2026 | Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE. | |
| Analizada | Media (6.5) | 0.19% | — | Apache Sling Security | 23/9/2026 | 6/10/2026 | A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. Users are recommended to upgrade to version 1.3.12, which fixes the issue. | |
| Analizada | Alta (7.3) | 0.13% | — | Apache Sling Security | 23/9/2026 | 6/10/2026 | A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue. | |
| Analizada | Media (6.1) | 0.35% | — | Apache Sling XSS Protection API | 23/9/2026 | 30/9/2026 | Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue. | |
| Analizada | Media (6.1) | 0.35% | — | Apache Sling XSS Protection API | 23/9/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue. | |
| Analizada | Media (6.1) | 0.35% | — | Apache Sling XSS Protection API | 23/9/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue. |