Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

224 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.4)——Maestro Grpc BrokerAI5/10/20265/10/2026
A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which…
RecibidaMedia (5.1)0.11%—Wso2 Message BrokerAI2/10/20263/10/2026
Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.
AnalizadaMedia (6.5)0.29%—Apache Qpid Broker-j25/9/20265/10/2026
Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker availability via processing without a decompressed-output…
AnalizadaAlta (7.5)0.37%—Apache Qpid Broker-j25/9/20265/10/2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
AnalizadaAlta (7.5)0.37%—Apache Qpid Broker-j25/9/20265/10/2026
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
AnalizadaAlta (7.5)0.37%—Apache Qpid Broker-j25/9/20265/10/2026
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
AnalizadaCrítica (9.8)0.38%—Apache Qpid Broker-j25/9/20265/10/2026
Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version…
AnalizadaAlta (7.5)0.32%—Apache Qpid Broker-j25/9/20265/10/2026
Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are…
AplazadaMedia (6.3)0.26%—Impress FOR IDX BrokerAI10/9/202610/9/2026
Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.
AplazadaMedia (6.5)0.42%—Impress FOR IDX BrokerAI10/9/202610/9/2026
Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.
Pendiente de análisisMedia (4.8)0.22%—Paloaltonetworks Cortex XDR Broker VMAI10/9/202611/9/2026
A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.
AnalizadaAlta (7.5)0.62%—Apache ActivemqApache Activemq ALLApache Activemq Broker9/9/202618/9/2026
Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All:…
Pendiente de análisisAlta (8.7)0.63%—Moos-ivp UfldshorebrokerAI3/9/202614/9/2026
MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing(). A single publisher can supply unbounded distinct community names to grow retained state and per-pass work without limit, causing memory exhaustion and…
Pendiente de análisisCrítica (9.3)0.26%—Moos-ivp UfldnodebrokerAI3/9/20268/9/2026
MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.
Pendiente de análisisCrítica (9.3)0.26%—Moos-ivp UfldshorsebrokerAI3/9/20268/9/2026
MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.
AplazadaAlta (7.5)0.38%—SOL BrokerAI7/8/202629/9/2026
In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server may silently drop the connection or send a CONNACK but fail to close…
AnalizadaMedia (6.5)0.65%—Apache Qpid Broker-j5/8/20266/8/2026
It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the…
AnalizadaMedia (6.5)0.65%—Apache Qpid Broker-j5/8/20266/8/2026
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the…
AnalizadaMedia (6.5)0.65%—Apache Qpid Broker-j5/8/20266/8/2026
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
AnalizadaMedia (6.5)0.65%—Apache Qpid Broker-j5/8/20266/8/2026
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
ModificadaAlta (7.5)0.77%—Apache Qpid Broker-j5/8/20266/8/2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
AnalizadaAlta (7.5)0.77%—Apache Qpid Broker-j5/8/20267/8/2026
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
AnalizadaAlta (7.5)0.77%—Apache Qpid Broker-j5/8/20267/8/2026
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
AnalizadaMedia (6.5)0.46%—Apache ActivemqApache Activemq ALLApache Activemq Broker28/7/20265/8/2026
Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated composite of real queues. This allows…
Pendiente de análisisMedia (5.5)0.11%—Dbus BrokerAI24/7/202610/9/2026
A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the…