Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.44% | — | Pentaho Data IntegrationAI | 11/9/2026 | 18/9/2026 | The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks. | |
| Analizada | Media (4.3) | 0.17% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 27/5/2026 | 24/7/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those… | |
| Analizada | Media (6.3) | 0.15% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 27/5/2026 | 24/7/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications. | |
| Analizada | Alta (7.7) | 0.20% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 27/5/2026 | 24/7/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities. | |
| Analizada | Alta (7.2) | 0.34% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 13/5/2026 | 30/9/2026 | Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data source administrator. | |
| Analizada | Crítica (9.1) | 0.38% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 10/3/2026 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE. | |
| Aplazada | Media (5.3) | 0.29% | — | Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho Analytics Community Dashboard FrameworkAI | 15/12/2025 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet. | |
| Aplazada | Alta (8.8) | 0.43% | — | Pentaho Data IntegrationAIPentaho Analytics Community Dashboard EditorAI | 15/12/2025 | 17/6/2026 | Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods. | |
| Aplazada | Media (4.9) | 0.42% | — | Hitachivantara Pentaho Business Analytics ServerAIHitachivantara Pentaho Data IntegrationAI | 16/4/2025 | 17/6/2026 | Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application that is… | |
| Aplazada | Media (6.8) | 0.49% | — | Hitachivantara Pentaho Data Integration AND AnalyticsAI | 16/4/2025 | 17/6/2026 | Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35) Description Hitachi Vantara Pentaho Data… | |
| Aplazada | Media (6.8) | 0.43% | — | Hitachivantara Pentaho Data IntegrationAI | 16/4/2025 | 17/6/2026 | Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35) Description Hitachi Vantara Pentaho Data… | |
| Aplazada | Crítica (9.1) | 0.94% | — | Hitachivantara Pentaho Data Integration AND AnalyticsAI | 16/4/2025 | 17/6/2026 | Overview The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99) Description Hitachi Vantara Pentaho Data Integration & Analytics versions before… | |
| Aplazada | Media (6.3) | 0.29% | — | Hitachivantara Pentaho Data Integration AND AnalyticsAI | 20/2/2025 | 17/6/2026 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522) Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving… | |
| Aplazada | Alta (8.8) | 0.72% | — | Hitachivantara Pentaho Data Integration AND AnalyticsAI | 19/2/2025 | 17/6/2026 | The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99) Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.9,… | |
| Aplazada | Alta (8.5) | 0.27% | — | Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho AnalyticsAI | 12/9/2024 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields. | |
| Analizada | Media (5.3) | 0.38% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 28/2/2024 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered. | |
| Modificada | Alta (8.8) | 0.64% | — | Hitachi Pentaho Data Integration AND Analytics | 12/12/2023 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Modificada | Media (6.5) | 12% | — | Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+25 | 24/1/2022 | 25/8/2026 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version… | |
| Modificada | Alta (7.5) | 7.4% | — | Apache Santuario XML Security FOR JavaApache CXFApache TomeeDebian Linux+14 | 19/9/2021 | 25/8/2026 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a… | |
| Modificada | Media (5.5) | 2.6% | — | Apache ANTOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Trade Finance+32 | 14/7/2021 | 25/8/2026 | When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR… | |
| Modificada | Media (5.5) | 2.5% | — | Apache ANTOracle Agile Product Lifecycle ManagementOracle Banking Trade FinanceOracle Banking Treasury Management+28 | 14/7/2021 | 25/8/2026 | When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected. | |
| Analizada | Crítica (9.8) | 96% | ⚠ Explotación activa | Apache StrutsOracle Business IntelligenceOracle Communications Diameter Intelligence HUBOracle Communications Policy Management+4 | 11/12/2020 | 17/6/2026 | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25. | |
| Modificada | Media (5.5) | 1.0% | — | Apache GroovyNetapp SnapcenterOracle Agile Engineering Data ManagementOracle Agile PLM Mcad Connector+17 | 7/12/2020 | 25/8/2026 | Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods… | |
| Modificada | Media (6.5) | 11% | — | Vmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRMOracle Communications Design Studio+34 | 19/9/2020 | 17/6/2026 | In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter. |