Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 212 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
182 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.74% | — | Apache Zookeeper | 16/9/2026 | 18/9/2026 | An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). When the ensemble name doesn't match, EnsembleAuthenticationProvider.handleAuthentication() logs the raw, unsanitized name… | |
| Analizada | Media (5.3) | 0.74% | — | Apache Zookeeper | 16/9/2026 | 18/9/2026 | When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with tab characters (\t) embedded in the username. Because the audit log uses tab-separated key=value format, the injected… | |
| Analizada | Alta (7.5) | 0.60% | — | Apache Zookeeper | 16/9/2026 | 18/9/2026 | The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless of the ACL restrictions on the znode or its parent. This opcode is considered internal-only and the official client doesn't have… | |
| Analizada | Alta (7.5) | 0.33% | — | Apache Zookeeper | 16/9/2026 | 18/9/2026 | Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and ssl.quorum.clientHostnameVerification=true are enabled, the Java SSLSocket quorum path accepts a CA-trusted peer certificate whose… | |
| Analizada | Alta (7.5) | 0.55% | — | Apache Zookeeper | 16/9/2026 | 18/9/2026 | Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths, then reconnecting after the paths are created with restricted ACLs. Issue is caused by incomplete fix for… | |
| Aplazada | Media (6.2) | 0.25% | — | MCP Memory KeeperAI | 15/9/2026 | 30/9/2026 | MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path to an export directory. An MCP client, including an LLM agent induced to call the… | |
| Aplazada | Media (4.2) | 0.26% | — | Doorkeeper Openid ConnectAI | 25/8/2026 | 9/9/2026 | Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this… | |
| Aplazada | Media (6.3) | 0.56% | — | DoorkeeperAI | 25/8/2026 | 9/9/2026 | Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its client_secret. This occurs because the… | |
| Aplazada | Baja (2.3) | 0.33% | — | Keeper.shAI | 19/8/2026 | 24/9/2026 | keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerability that allows authenticated attackers to reach private network addresses by exploiting a DNS rebinding attack against the two-phase URL validation and connection flow. The SSRF guard validates a… | |
| Aplazada | Alta (7.9) | 0.43% | — | Upkeeper Solutions Upkeeper Instant Privilege AccessAI | 24/6/2026 | 25/6/2026 | Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tampering-Forging. This issue affects upKeeper Instant Privilege Access: through 1.6.1. | |
| Aplazada | Crítica (9.4) | 0.23% | — | Line Centraldogma-serverAIApache ZookeeperAI | 22/6/2026 | 22/6/2026 | A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an… | |
| Analizada | Alta (8.7) | 0.73% | — | Image-sizeRedhat DiscoveryRedhat GatekeeperRedhat Trusted Artifact Signer+1 | 9/6/2026 | 24/7/2026 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by… | |
| Pendiente de análisis | Alta (7.4) | 0.27% | — | Upkeeper Solutions Upkeeper Instant Privilege AccessAI | 14/4/2026 | 17/6/2026 | .NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Hijacking a Privileged Thread of Execution.This issue affects upKeeper Instant Privilege Access: through 1.5.0. | |
| Pendiente de análisis | Crítica (9) | 0.33% | — | Upkeeper Solutions Upkeeper Instant Privilege AccessAI | 14/4/2026 | 17/6/2026 | Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Hijacking a Privileged Thread of Execution.This issue affects upKeeper Instant Privilege Access: through 1.5.0. | |
| Analizada | Alta (8.1) | 0.51% | — | ORY Oathkeeper | 26/3/2026 | 17/6/2026 | ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to authentication bypass due to cache key confusion. The `oauth2_introspection` authenticator cache does not distinguish tokens that… | |
| Analizada | Media (6.5) | 0.28% | — | ORY Oathkeeper | 26/3/2026 | 17/6/2026 | ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Ory Oathkeeper is often deployed behind other components like CDNs, WAFs, or reverse proxies. Depending on the setup, another component might forward the request to the… | |
| Analizada | Crítica (10) | 0.64% | — | ORY Oathkeeper | 26/3/2026 | 17/6/2026 | ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP path traversal. An attacker can craft a URL containing path traversal sequences (e.g.… | |
| Modificada | Alta (7.5) | 1.2% | — | Apache Zookeeper | 7/3/2026 | 15/7/2026 | Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering potential production systems affected by… | |
| Modificada | Alta (7.4) | 0.63% | — | Apache Zookeeper | 7/3/2026 | 15/7/2026 | Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a… | |
| Aplazada | Alta (7.1) | 0.46% | — | Odine Solutions GatekeeperAI | 16/1/2026 | 17/6/2026 | Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicious database queries. Attackers can exploit the vulnerability by sending crafted payloads to the /rass/api/v1/trafficCycle/ endpoint to manipulate PostgreSQL database… | |
| Aplazada | Media (6.1) | 0.29% | — | Shabat KeeperAI | 9/1/2026 | 17/6/2026 | The Shabat Keeper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] parameter in all versions up to, and including, 0.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (6.5) | 0.19% | — | GET Bowtied Shopkeeper ExtenderAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Get Bowtied Shopkeeper Extender shopkeeper-extender allows Stored XSS.This issue affects Shopkeeper Extender: from n/a through < 7.0. | |
| Analizada | Alta (7.3) | 0.23% | — | Upkeeper Manager | 19/11/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.2.0 before 5.2.12. | |
| Aplazada | Media (6.2) | 0.14% | — | PgcodekeeperAI | 24/10/2025 | 17/6/2026 | An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of passwords and usernames. | |
| Aplazada | Alta (8.2) | 0.34% | — | PgcodekeeperAI | 24/10/2025 | 17/6/2026 | The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file, deserialization may result in unintended code execution or other malicious behavior on the target system. |