Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.19% | — | Apache Sling Security BundleAI | 23/9/2026 | 23/9/2026 | A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. Users are recommended to upgrade to version 1.3.12, which fixes the issue. | |
| Pendiente de análisis | Alta (7.3) | 0.13% | — | Apache Sling Security BundleAI | 23/9/2026 | 23/9/2026 | A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue. | |
| Analizada | Media (6.1) | 0.35% | — | Apache Sling XSS Protection API | 23/9/2026 | 30/9/2026 | Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue. | |
| Analizada | Media (6.1) | 0.35% | — | Apache Sling XSS Protection API | 23/9/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue. | |
| Analizada | Media (6.1) | 0.35% | — | Apache Sling XSS Protection API | 23/9/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue. | |
| Analizada | Media (6.1) | 0.47% | — | Apache Sling XSS Protection API | 23/9/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue. | |
| Analizada | Media (6.1) | 0.35% | — | Apache Sling XSS Protection API | 23/9/2026 | 30/9/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack in every feature using this method. In order to… | |
| Aplazada | Alta (8.1) | 0.43% | — | GunslingerAI | 17/6/2026 | 30/9/2026 | Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions. | |
| Aplazada | Media (6.4) | 0.20% | — | Funnelkit SlingblocksAI | 21/8/2025 | 17/6/2026 | The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block's attributes in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Analizada | Media (5.4) | 0.22% | — | Funnelkit Slingblocks | 8/3/2025 | 17/6/2026 | The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Icon List" Block in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.31% | — | Funnelkit SlingblocksAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FunnelKit SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) allows Stored XSS.This issue affects SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels): from n/a through 1.4.1. | |
| Modificada | Alta (7.5) | 1.3% | — | Apache Sling Servlets Resolver | 6/2/2024 | 17/6/2026 | Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. However, whether a system is vulnerable to this attack depends on the exact configuration of the system. If the system is vulnerable,… | |
| Modificada | Crítica (9.8) | 2.2% | — | Apache Sling Commons Json | 15/5/2023 | 17/6/2026 | Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are encouraged to consider the Apache Sling… | |
| Analizada | Crítica (9) | 1.1% | — | Apache Sling Engine | 13/4/2023 | 17/6/2026 | The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resource with specific content-type and control the include path… | |
| Modificada | Alta (7.5) | 1.5% | — | Apache Sling Resource Merger | 20/3/2023 | 17/6/2026 | Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache Sling Resource Merger: from 1.2.0 before 1.4.2. | |
| Modificada | Media (6.5) | 1.1% | — | Apache Sling I18n | 23/2/2023 | 17/6/2026 | Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n dictionaries in the repository in a location the author has write access to. As these translations are used across the whole product, it allows an author to change any text or dialog in the product.… | |
| Modificada | Alta (7.5) | 1.2% | — | Apache Sling JCR Base | 14/2/2023 | 17/6/2026 | Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility functions in RepositoryAccessor. The functions getRepository and getRepositoryFromURL allow an application to access data stored in a remote location via JDNI and RMI. Users… | |
| Modificada | Media (6.1) | 1.4% | — | Apache Sling CMS | 4/2/2023 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in multiple features. Upgrade to Apache Sling App CMS >= 1.1.6 | |
| Modificada | Media (5.4) | 1.4% | — | Apache Sling CMS | 9/1/2023 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in the site group feature. Upgrade to Apache Sling App CMS >= 1.1.4 | |
| Modificada | Media (5.4) | 1.5% | — | Apache Sling CMS | 2/11/2022 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management feature. | |
| Modificada | Crítica (9.8) | 1.5% | — | HPE Slingshot FirmwareHPE Cray EX Supercomputers FirmwareHPE Cray SH Supercomputer AIR Cooled Base System Code FirmwareHPE Cray SH Supercomputer Liquid Cooled Base System Code Firmware+1 | 24/6/2022 | 17/6/2026 | A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX… | |
| Modificada | Media (5.3) | 2.4% | — | Apache Sling APIApache Sling Commons LOG | 22/6/2022 | 17/6/2026 | Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files. | |
| Modificada | Alta (7.4) | 1.9% | — | Apache Sling Commons Messaging Mail | 14/12/2021 | 17/6/2026 | Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "man in the middle" attacks additional server identity checks must be performed when accessing mail servers. For compatibility reasons these additional checks are disabled… | |
| Modificada | Media (6.1) | 2.0% | — | Apache Sling CMS | 1/4/2020 | 17/6/2026 | Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks. | |
| Modificada | Media (6.1) | 2.9% | — | Apache Sling XSS Protection APIApache Sling XSS Protection API Compat | 10/1/2018 | 17/6/2026 | A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected versions are Apache Sling XSS Protection API 1.0.4 to 1.0.18,… |