Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3874 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.47% | — | Apache Sling XSS Protection API | 23/9/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue. | |
| Analizada | Media (6.1) | 0.35% | — | Apache Sling XSS Protection API | 23/9/2026 | 30/9/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack in every feature using this method. In order to… | |
| Pendiente de análisis | Alta (7.5) | 0.54% | — | Apache DorisAI | 23/9/2026 | 23/9/2026 | An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected endpoints relied on client-supplied node information for authentication without providing sufficient authentication of the… | |
| Pendiente de análisis | Crítica (9.8) | 0.42% | — | Apache BuildstreamAI | 23/9/2026 | 23/9/2026 | Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks as part of source fetching. The impact of… | |
| Aplazada | Crítica (9.1) | 0.27% | — | Apache Http ServerAI | 22/9/2026 | 23/9/2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users. | |
| Aplazada | Alta (8.4) | 0.13% | — | Apache Http ServerAIOpensslAI | 22/9/2026 | 23/9/2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution. | |
| Pendiente de análisis | Alta (8.8) | 0.64% | — | Apache Calcite AvaticaAI | 22/9/2026 | 22/9/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avatica. Plugin instantiation (via AvaticaUtils#instantiatePlugin and other methods) initializes arbitrary classes via unrestricted calls to Class.forName(String) which by default triggers initialization.… | |
| Pendiente de análisis | Crítica (9.8) | 0.39% | — | Apache MinaAI | 21/9/2026 | 22/9/2026 | The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never… | |
| Analizada | Crítica (9.1) | 0.75% | — | Apache Airflow | 21/9/2026 | 25/9/2026 | Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An… | |
| Analizada | Media (4.2) | 0.73% | — | Apache Airflow | 21/9/2026 | 25/9/2026 | When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The request then executes -- and is recorded in the audit log -- as the… | |
| Analizada | Media (4.3) | 0.64% | — | Apache Airflow | 21/9/2026 | 25/9/2026 | Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore enumerate asset events — including the source Dag ID, task ID, run ID and event… | |
| Analizada | Media (4.3) | 0.50% | — | Apache Neethi | 21/9/2026 | 25/9/2026 | When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue. | |
| Analizada | Alta (7.5) | 0.74% | — | Apache Neethi | 21/9/2026 | 25/9/2026 | A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue. | |
| Analizada | Alta (7.5) | 0.74% | — | Apache Neethi | 21/9/2026 | 25/9/2026 | A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue. | |
| Analizada | Alta (7.5) | 0.74% | — | Apache Neethi | 21/9/2026 | 25/9/2026 | A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue. | |
| Analizada | Alta (7.5) | 0.76% | — | Apache Neethi | 21/9/2026 | 24/9/2026 | A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue. | |
| Pendiente de análisis | Alta (7.5) | 0.49% | — | Apache MinaAI | 21/9/2026 | 21/9/2026 | The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what. Some compressed data may have a compression ration greater than 1 thousand, leading to an exhaustion of the application… | |
| Pendiente de análisis | Alta (8.6) | 0.78% | — | OpeneqellaAIApache FreemarkerAI | 20/9/2026 | 24/9/2026 | openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerPortletRenderer.renderHtml() that allows any authenticated non-guest user to achieve remote code execution by storing a malicious FreeMarker payload through a POST request to the RemotePortletService… | |
| Pendiente de análisis | Alta (7.5) | 0.44% | 💥 PoC | Apache AirflowAI | 18/9/2026 | 22/9/2026 | Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently suppressing asset-triggered scheduling for it — a state-changing action gated on a… | |
| Aplazada | Media (5.8) | 0.40% | — | MetacatAIApache SolrAIApache SolrjAI | 17/9/2026 | 23/9/2026 | Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the client-controlled qt parameter through Apache SolrJ from search endpoints such as /d1/mn/v2/query/solr/ to its privileged Solr backend. An unauthenticated client can select… | |
| Pendiente de análisis | Alta (7.5) | 0.49% | — | Apache KarafAI | 17/9/2026 | 18/9/2026 | Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader's pinned in… | |
| Pendiente de análisis | Crítica (9.8) | 0.49% | — | Apache Myfaces CoreAI | 16/9/2026 | 17/9/2026 | Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected. Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue. | |
| Analizada | Alta (7.2) | 0.79% | — | Apache Nifi | 16/9/2026 | 21/9/2026 | Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and… | |
| Analizada | Baja (2.3) | 0.44% | — | Apache Nifi | 16/9/2026 | 21/9/2026 | Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connector alone, without evaluating access to the Process Groups… | |
| Analizada | Media (5.9) | 0.48% | — | Apache Nifi | 16/9/2026 | 21/9/2026 | Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework authorization for these methods was limited to read and… |