Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 557 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | — | — | Eclipse Basyx AAS WEB UIAI | 1/10/2026 | 1/10/2026 | In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted… | |
| Pendiente de análisis | Alta (7.1) | 0.15% | — | Eclipse ThreadxAI | 29/9/2026 | 29/9/2026 | `_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection… | |
| Pendiente de análisis | Media (5.7) | 0.07% | — | Eclipse ThreadxAI | 29/9/2026 | 29/9/2026 | Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image length, so every size/offset field in `TXM_MODULE_PREAMBLE` is fully… | |
| Pendiente de análisis | Crítica (9.3) | 0.10% | — | Eclipse ThreadxAI | 29/9/2026 | 30/9/2026 | Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can register an arbitrary function pointer as the global trace-full callback. The kernel calls it directly —… | |
| Pendiente de análisis | Alta (8.7) | 0.44% | — | Eclipse Open VSXAI | 22/9/2026 | 22/9/2026 | The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore issue credentialed requests to the service in a logged-in user's browser and read the… | |
| Aplazada | Baja (1) | 0.15% | — | Eclipse Iceoryx2AI | 21/9/2026 | 21/9/2026 | In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid &str and trigger undefined behavior using entirely… | |
| Aplazada | Crítica (9.1) | 0.34% | — | Eclipse Open VSXAI | 21/9/2026 | 22/9/2026 | UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a trusted proxy, falling back to the client-supplied Host header. Those responses are… | |
| Pendiente de análisis | Media (4.8) | 0.30% | — | Eclipse AnkaiosAI | 17/9/2026 | 18/9/2026 | In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized access to another workload's logs. | |
| Pendiente de análisis | Alta (8.4) | 0.11% | — | Eclipse AnkaiosAI | 14/9/2026 | 16/9/2026 | In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a directory or FIFO already exists at that path when the agent (re)starts, the agent… | |
| Aplazada | Alta (8.2) | 1.1% | — | Xwiki PlatformAIEclipse JettyAIApache TomcatAI | 14/9/2026 | 30/9/2026 | XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix when Jetty 12 or later decodes the request path. The affected lookup is replaced… | |
| Pendiente de análisis | Crítica (9.1) | 0.54% | — | Eclipse Embedded CDTAIARM Cmsis-packAI | 14/9/2026 | 16/9/2026 | In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk. | |
| Aplazada | Crítica (9.9) | 0.55% | — | Eclipse AeriosAIKeycloakAIPostgresqlAIOpenldapAI | 8/9/2026 | 9/9/2026 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak service and its PostgreSQL backing database… | |
| Aplazada | Crítica (9.2) | 0.34% | — | Eclipse Ditto Javascript Client NodeAIEclipse Ditto Javascript Client Node 1AI | 8/9/2026 | 9/9/2026 | In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the… | |
| Aplazada | Alta (8.7) | 0.25% | — | Eclipse JettyAI | 8/9/2026 | 9/9/2026 | A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race condition in the server when handling RST_STREAM frames and GOAWAY frames sent by the client.… | |
| Aplazada | Media (6.3) | 0.39% | — | Eclipse CHEAI | 8/9/2026 | 8/9/2026 | In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering. An authenticated user can exploit this server-side request forgery (SSRF) to read responses from internal… | |
| Aplazada | Media (6.8) | 0.16% | — | Eclipse AnkaiosAI | 7/9/2026 | 8/9/2026 | In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation… | |
| Aplazada | Alta (8.7) | 0.31% | — | Eclipse JettyAI | 7/9/2026 | 8/9/2026 | A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enabled, as unknown opcodes bypass the normal maximum frame size handling and payload… | |
| Aplazada | Alta (8.3) | 0.16% | — | Eclipse AnkaiosAI | 7/9/2026 | 8/9/2026 | In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An authenticated workload with access restricted by such a rule can submit a CompleteStateRequest or UpdateStateRequest with an empty… | |
| Aplazada | Alta (8.3) | 0.27% | — | Eclipse AeriosAIEclipse FederatorAI | 3/9/2026 | 3/9/2026 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or set to false, the component configures… | |
| Aplazada | Alta (8.8) | 0.91% | — | Eclipse AeriosAI | 3/9/2026 | 3/9/2026 | Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or delete Self-orchestrator resources were incorporated into filesystem paths without adequate validation or sanitization. An unauthenticated remote… | |
| Aplazada | Crítica (9.5) | 0.34% | — | Eclipse ArrowheadAIApache TomcatAI | 3/9/2026 | 3/9/2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate that the client sends inside the MQTT message payload (the authentication field of MqttRequestTemplate) and treats its Subject DN as the… | |
| Aplazada | Alta (8.9) | 0.47% | — | Eclipse ArrowheadAIApache TomcatAIVmware Spring MVCAIVmware Spring SecurityAI | 3/9/2026 | 3/9/2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on… | |
| Aplazada | Crítica (9) | 0.18% | — | Eclipse AeriosAIKrakendAI | 2/9/2026 | 3/9/2026 | In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through the Helm chart configuration. This setting disables TLS… | |
| Aplazada | Alta (7.6) | 0.41% | — | Eclipse DittoAI | 2/9/2026 | 3/9/2026 | In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_id }}) resolved from inbound message headers into a pre-configured JSON "thing" template as raw, un-escaped strings, and… | |
| Aplazada | Media (5.3) | 0.40% | — | Eclipse DittoAI | 2/9/2026 | 3/9/2026 | In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a Thing or Feature, without validating the target host, and follows HTTP redirects without re-validating the redirect target and without a hop limit.… |