Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.31% | — | Akka.netAI | 6/10/2025 | 17/6/2026 | Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enabled via our `akka.remote.dot-netty.tcp` transport and this would correctly enforce private key validation on the server-side of inbound connections. Akka.Remote, however,… | |
| Aplazada | Media (6) | 0.22% | — | Akka-cluster-metricsAI | 28/6/2025 | 17/6/2026 | In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics. | |
| Analizada | Media (6.5) | 0.75% | — | Apache Pekko ManagementAkka Management | 3/6/2025 | 17/6/2026 | If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. Akka was… | |
| Aplazada | Alta (8.8) | 0.25% | — | Krishankakkar Gap-hub-user-roleAI | 31/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in krishankakkar gap-hub-user-role gap-hub-user-role allows Authentication Bypass.This issue affects gap-hub-user-role: from n/a through <= 3.4.1. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (5.5) | 0.15% | — | Lightbend Akka Http | 21/5/2023 | 17/6/2026 | When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak permissions: it is readable by other users on Linux or UNIX, a similar issue to CVE-2022-41946. | |
| Modificada | Alta (7.5) | 0.65% | — | Lightbend Akka ActorLightbend Akka Discovery | 11/5/2023 | 17/6/2026 | In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictable DNS transaction IDs when resolving DNS records, making DNS resolution subject to poisoning by an attacker. If the application performing discovery does not validate (e.g., via… | |
| Modificada | Media (5.5) | 0.15% | — | Lightbend Alpakka Kafka | 27/4/2023 | 17/6/2026 | Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor. | |
| Modificada | Alta (7.5) | 36% | — | Akka Http Server | 2/11/2021 | 17/6/2026 | Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments. | |
| Modificada | Media (4.4) | 1.2% | — | Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager | 22/7/2021 | 17/6/2026 | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning… | |
| Modificada | Crítica (9.8) | 3.0% | — | Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager | 22/7/2021 | 17/6/2026 | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from `shell` to `exec` and providing the ssh client a single execution parameter. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2… | |
| Modificada | Crítica (9.8) | 1.3% | — | Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager | 22/7/2021 | 17/6/2026 | Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later). | |
| Modificada | Alta (8.8) | 1.3% | — | Akkadianlabs Akkadian Provisioning Manager | 1/7/2021 | 17/6/2026 | An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user to escape the web configuration file editor and escalate privileges. | |
| Modificada | Alta (7.5) | 6.8% | — | Akkadianlabs Akkadian Provisioning Manager | 1/7/2021 | 17/6/2026 | An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories. | |
| Modificada | Media (6.5) | 0.71% | — | Lightbend Akka-http | 17/2/2021 | 17/6/2026 | This affects all versions before 10.1.14 and from 10.2.0 to 10.2.4 of package com.typesafe.akka:akka-http-core. It allows multiple Transfer-Encoding headers. | |
| Modificada | Alta (8.8) | 0.52% | — | Softwaremill Akka-http-session | 20/1/2021 | 17/6/2026 | This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and before 0.6.1; all versions of package com.softwaremill.akka-http-session:core_2.11; the package com.softwaremill.akka-http-session:core_2.13 from 0 and before 0.6.1. CSRF protection can be bypassed by forging a request that contains the… | |
| Modificada | Alta (8.8) | 0.65% | — | Softwaremill Akka-http-session | 27/11/2020 | 17/6/2026 | This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by randomTokenCsrfProtection could be bypassed… | |
| Modificada | Alta (7.5) | 3.1% | — | Lightbend Akka Http | 30/8/2018 | 17/6/2026 | The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb. | |
| Modificada | Crítica (9.1) | 1.2% | — | Lightbend Akka | 29/8/2018 | 17/6/2026 | Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error. A random number generator is used in Akka Remoting for TLS (both classic and Artery Remoting). Akka allows configuration of custom random number generators. For historical reasons, Akka included the… | |
| Modificada | Alta (7.5) | 1.1% | — | Akka Http Server | 5/10/2017 | 17/6/2026 | Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service | |
| Modificada | Alta (8.1) | 6.2% | — | Akka | 17/7/2017 | 17/6/2026 | Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem. | |
| Modificada | Media (5) | 3.1% | — | Rakkarsoft Raknet | 9/6/2005 | 16/6/2026 | Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP packet. |