Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 86 respecto a la semana anterior
Críticas / altas1460▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)91▼ 420 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.5) | 0.34% | — | Eclipse ArrowheadAIApache TomcatAI | 3/9/2026 | 3/9/2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate that the client sends inside the MQTT message payload (the authentication field of MqttRequestTemplate) and treats its Subject DN as the… | |
| Aplazada | Alta (8.9) | 0.47% | — | Eclipse ArrowheadAIApache TomcatAIVmware Spring MVCAIVmware Spring SecurityAI | 3/9/2026 | 3/9/2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on… | |
| Analizada | Media (6.6) | 0.49% | — | 101arrowz Fflate | 22/7/2026 | 19/8/2026 | fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads… | |
| Aplazada | Alta (8.4) | 0.17% | — | Tildearrow FurnaceAI | 24/3/2026 | 17/6/2026 | Out-of-bounds Read vulnerability in tildearrow furnace (extern/libsndfile-modified/src modules). This vulnerability is associated with program files flac.C. This issue affects furnace: before 0.7. | |
| Analizada | Alta (7) | 0.82% | — | Apache Arrow | 17/2/2026 | 17/6/2026 | Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as Binary View and String View data).… | |
| Aplazada | Crítica (10) | 0.30% | — | Tildearrow FurnaceAIZlibAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in tildearrow furnace (extern/zlib modules). This vulnerability is associated with program files inflate.C. | |
| Aplazada | Media (6.5) | 0.22% | — | Arrowplugins Arrow Custom Feed FOR TwitterAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arrow Plugins Arrow Custom Feed for Twitter arrow-twitter-feed allows Stored XSS.This issue affects Arrow Custom Feed for Twitter: from n/a through <= 1.5.3. | |
| Aplazada | Alta (7.1) | 0.39% | — | Arrowplugins Arrow MapsAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arrow Plugins Arrow Maps ap-google-maps allows Reflected XSS.This issue affects Arrow Maps: from n/a through <= 1.0.9. | |
| Analizada | Crítica (9.8) | 2.3% | — | Apache Arrow | 28/11/2024 | 17/6/2026 | Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example, user-supplied input files). This vulnerability only… | |
| Analizada | Crítica (9.1) | 0.60% | — | Arrowjs Arrowcms | 23/8/2024 | 17/6/2026 | A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the… | |
| Analizada | Alta (7.5) | 0.71% | — | Apache Arrow | 23/7/2024 | 17/6/2026 | Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens. On certain error conditions, the logs may contain the OIDC token passed to AssumeRoleWithWebIdentity… | |
| Modificada | Crítica (9.8) | 15% | — | Apache Pyarrow | 9/11/2023 | 17/6/2026 | Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example user-supplied input files). This vulnerability only affects PyArrow, not… | |
| Modificada | Media (6.1) | 0.33% | — | Arrowplugins THE Awesome Feed | 26/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plugin <= 2.2.5 versions. | |
| Modificada | Media (6.1) | 0.33% | — | Arrowplugins Social Feed | 17/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins Social Feed | Custom Feed for Social Media Networks plugin <= 2.2.0 versions. | |
| Modificada | Media (5.4) | 0.33% | — | Arrowplugins THE Awesome Feed | 2/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plugin <= 2.2.5 versions. | |
| Modificada | Alta (7.2) | 1.3% | — | Kratosdefense Spectralnet Narrowband Firmware | 12/6/2023 | 17/6/2026 | A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband (NB) before 1.7.5. As an admin user, an attacker can send a crafted password in order to execute Linux commands as the root user. | |
| Modificada | Alta (7.8) | 0.26% | — | Xarrow | 16/5/2022 | 17/6/2026 | xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges. | |
| Modificada | Media (6.1) | 0.79% | — | Xarrow | 16/5/2022 | 17/6/2026 | xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code. | |
| Modificada | Media (6.1) | 0.79% | — | Xarrow | 16/5/2022 | 17/6/2026 | xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisvalue.htm, which may allow an unauthorized attacker to execute arbitrary code. | |
| Modificada | Media (6.1) | 0.57% | — | Surveysparrow Enterprise Survey Software | 11/5/2022 | 17/6/2026 | Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter. | |
| Modificada | Media (5.4) | 2.4% | — | Surveysparrow Enterprise Survey Software | 11/5/2022 | 17/6/2026 | Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter. | |
| Modificada | Media (6.5) | 1.2% | — | Tildearrow Furnace | 10/4/2022 | 17/6/2026 | A denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. This is due to an incomplete fix of CVE-2022-1211. It is possible to initiate the attack remotely but it requires user interaction. The issue got fixed with the patch 0eb02422d5161767e9983bdaa5c429762d3477ce. | |
| Modificada | Media (6.5) | 0.91% | — | Tildearrow Furnace | 3/4/2022 | 17/6/2026 | A vulnerability classified as critical has been found in tildearrow Furnace dev73. This affects the FUR to VGM converter in console mode which causes stack-based overflows and crashes. It is possible to initiate the attack remotely but it requires user-interaction. A POC has been disclosed to the public and may be… | |
| Modificada | Alta (7.5) | 4.6% | — | Apache Arrow | 8/11/2019 | 17/6/2026 | While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby and R implementations. The uninitialized memory could potentially be… | |
| Modificada | Alta (7.5) | 3.3% | — | Apache Arrow | 8/11/2019 | 17/6/2026 | It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uninitialized memory bug when building arrays with null values in some cases. This can lead to uninitialized memory being unintentionally shared if Arrow Arrays are transmitted… |