Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.74% | — | Apache Qpid Protonj2 | 5/8/2026 | 7/8/2026 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the… | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Protonj2 | 5/8/2026 | 7/8/2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Protonj2 | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the… | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the… | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Protonj2 | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Protonj2 | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | |
| Modificada | Alta (7.4) | 2.5% | — | Apache Qpid Proton-j | 13/11/2018 | 17/6/2026 | The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a verification mode was explicitly configured, client and server modes previously defaulted as documented to not verifying a peer certificate, with options to configure this… | |
| Modificada | Media (5.9) | 1.6% | — | Apache Qpid Proton | 2/5/2017 | 17/6/2026 | The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when using the SChannel-based security layer, which allows… | |
| Modificada | Media (6.5) | 4.3% | — | Apache Qpid ProtonFedoraproject Fedora | 12/4/2016 | 17/6/2026 | The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle attackers to obtain sensitive… |