Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.57% | — | HPE Icewall Federation AgentAIHPE Icewall ProxyAI | 11/9/2026 | 11/9/2026 | A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS). | |
| Pendiente de análisis | Crítica (9.4) | 0.63% | — | Amazon Athena Query FederationAIAmazon NeptuneAIAmazon AthenaAIAmazon LambdaAI | 21/8/2026 | 27/8/2026 | In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later. | |
| Pendiente de análisis | Crítica (9.8) | 0.32% | — | Picketlink FederationAI | 11/8/2026 | 25/9/2026 | A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws. | |
| Pendiente de análisis | Alta (8.7) | 0.71% | — | Divvypayhq Absinthe FederationAI | 7/8/2026 | 12/8/2026 | Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abort the Erlang VM via crafted _entities representation keys. Every key of every object in the representations argument of the federation-mandated _entities field is… | |
| Pendiente de análisis | Media (6.1) | 0.59% | — | Amazon Aws-athena-query-federationAI | 17/7/2026 | 20/7/2026 | Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. Improper… | |
| Aplazada | Media (6.5) | 0.38% | — | Activitypub-federation-rustAIJoin-lemmy LemmyAI | 27/3/2026 | 17/6/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `activitypub-federation-rust` (`src/utils.rs`) does not check for `Ipv4Addr::UNSPECIFIED` (0.0.0.0). An unauthenticated attacker controlling a remote domain can point it to 0.0.0.0, bypass the SSRF… | |
| Aplazada | Crítica (9.9) | 0.56% | — | Apollo FederationAI | 16/3/2026 | 17/6/2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within the gateway that may allow pollution of Object.prototype in certain scenarios. A malicious client may be able to pollute… | |
| Aplazada | Alta (7.7) | 0.42% | — | Activitypub FederationAIPict-rsAIJoin-lemmy LemmyAI | 6/3/2026 | 17/6/2026 | Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. Prior to version 0.19.16, the GET /api/v4/image/{filename} endpoint is vulnerable to unauthenticated SSRF through parameter… | |
| Aplazada | Alta (7.5) | 0.38% | — | Apollo FederationAIApollo RouterAIAvirt RoverAI | 13/11/2025 | 17/6/2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions of Apollo Federation's composition logic prior to 2.9.5, 2.10.4, 2.11.5, and 2.12.1 allowed some queries to Apollo Router to improperly bypass access controls on types/fields. Apollo Federation… | |
| Analizada | Media (6.1) | 0.20% | — | IBM Business Automation WorkflowIBM Process Federation Server | 6/11/2025 | 17/6/2026 | IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an… | |
| Analizada | Media (6.5) | 0.32% | — | Open-federation Json-schema-editor-visual | 24/9/2025 | 17/6/2026 | json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers to inject or delete properties on Object.prototype via supplying a crafted payload, causing denial of… | |
| Aplazada | Media (4) | 0.42% | — | Activitypub FederationAIJoin-lemmy LemmyAI | 10/2/2025 | 17/6/2026 | Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vulnerability, which is present in versions 0.6.2 and prior of activitypub_federation and versions 0.19.8 and prior of… | |
| Aplazada | Alta (7.5) | 0.50% | — | Openairinterface MagmaAIOpenairinterface OAI EPC FederationAI | 15/11/2024 | 17/6/2026 | Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cause a Denial of Service (DoS) via a crafted NGAP packet. | |
| Aplazada | Media (6.5) | 0.46% | — | OAI EPC FederationAILinuxfoundation MagmaAI | 15/11/2024 | 17/6/2026 | Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet. | |
| Modificada | Media (6.5) | 1.5% | — | IBM Cloud PAK FOR AutomationIBM Process Federation Server | 2/4/2020 | 17/6/2026 | The IBM Process Federation Server 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, and 19.0.0.3 Global Teams REST API does not properly shutdown the thread pools that it creates to retrieve Global Teams information from the federated systems. As a consequence, the Java Virtual Machine can't recover the memory used by those… | |
| Modificada | Alta (8.6) | 8.0% | — | Microsoft Active Directory Federation Services | 18/9/2018 | 17/6/2026 | Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls. | |
| Modificada | Alta (7.5) | 4.5% | — | Canonical Ubuntu LinuxXmlsoft Libxml2Debian LinuxHP Icewall Federation Agent+2 | 30/7/2018 | 17/6/2026 | It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705. | |
| Modificada | Media (6.1) | 1.7% | — | HP Icewall Federation Agent | 15/2/2018 | 17/6/2026 | A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found. | |
| Modificada | Media (5.9) | 42% | — | OpensslHP Icewall Federation AgentHP Icewall McrpHP Icewall SSO+5 | 26/9/2016 | 17/6/2026 | The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c. | |
| Modificada | Crítica (9.8) | 44% | — | HP Icewall Federation AgentHP Icewall McrpHP Icewall SSOHP Icewall SSO Agent Option+2 | 16/9/2016 | 17/6/2026 | The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Crítica (9.8) | 7.0% | — | HP Icewall Federation AgentApple WatchosApple MAC OS XXmlsoft Libxml2+15 | 9/6/2016 | 17/6/2026 | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. | |
| Modificada | Alta (7.5) | 14% | — | HP Icewall Federation AgentCanonical Ubuntu LinuxDebian LinuxOracle VM Server+7 | 9/6/2016 | 17/6/2026 | The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName. | |
| Modificada | Alta (7.5) | 5.1% | — | Canonical Ubuntu LinuxXmlsoft Libxml2Debian LinuxHP Icewall Federation Agent+2 | 17/5/2016 | 17/6/2026 | The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of… | |
| Modificada | Alta (7.5) | 7.0% | — | Opensuse LeapDebian LinuxHP Icewall Federation AgentHP Icewall File Manager+10 | 17/5/2016 | 17/6/2026 | The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document. | |
| Modificada | Media (5) | 5.9% | — | Debian LinuxCanonical Ubuntu LinuxXmlsoft Libxml2Redhat Enterprise Linux Desktop+5 | 15/12/2015 | 17/6/2026 | The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read. |