Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.37% | — | Wxiaoqi Spring Cloud PlatformAI | 13/9/2026 | 15/9/2026 | A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization. The attack can be executed remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.37% | — | Wxiaoqi Spring Cloud PlatformAI | 13/9/2026 | 14/9/2026 | A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation leads to missing authorization. Remote exploitation of the… | |
| Analizada | Alta (8.1) | 0.69% | — | Microsoft Spring Cloud | 8/9/2026 | 29/9/2026 | Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.3) | 0.40% | — | Vmware Spring Cloud Config | 27/8/2026 | 31/8/2026 | The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier | |
| Analizada | Baja (3.8) | 0.23% | — | Vmware Spring Cloud Stream | 27/8/2026 | 4/9/2026 | Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |
| Analizada | Baja (3.8) | 0.21% | — | Vmware Spring Cloud Stream | 27/8/2026 | 4/9/2026 | Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |
| Analizada | Baja (3.8) | 0.21% | — | Vmware Spring Cloud Stream | 27/8/2026 | 4/9/2026 | Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |
| Analizada | Baja (3.8) | 0.21% | — | Vmware Spring Cloud Stream | 27/8/2026 | 4/9/2026 | Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |
| Analizada | Media (4.9) | 0.23% | — | Vmware Spring Cloud Function | 27/8/2026 | 4/9/2026 | Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 | |
| Analizada | Baja (3.5) | 0.21% | — | Vmware Spring Cloud Function | 27/8/2026 | 2/9/2026 | Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier | |
| Analizada | Baja (3.5) | 0.21% | — | Vmware Spring Cloud Function | 27/8/2026 | 2/9/2026 | Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier | |
| Analizada | Baja (3.5) | 0.22% | — | Vmware Spring Cloud Function | 27/8/2026 | 2/9/2026 | Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier | |
| Analizada | Baja (3.5) | 0.13% | — | Vmware Spring Cloud Function | 27/8/2026 | 2/9/2026 | Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 | |
| Analizada | Media (5.5) | 0.24% | — | Vmware Spring Cloud Function | 27/8/2026 | 31/8/2026 | Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 | |
| Analizada | Alta (7.6) | 0.43% | — | Broadcom Spring Cloud Commons | 27/8/2026 | 1/9/2026 | There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commons 5.0.0 - 5.0.2 Spring Cloud Commons 4.3.0 - 4.3.3 Spring Cloud Commons 4.0.0 - 4.2.6 Spring Cloud Commons 3.1.10 and earlier | |
| Analizada | Media (4.9) | 0.17% | — | Vmware Spring Cloud Function | 27/8/2026 | 23/9/2026 | Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |
| Analizada | Alta (7.5) | 0.49% | — | Vmware Spring Cloud Config | 27/8/2026 | 1/9/2026 | Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier | |
| Analizada | Alta (8.7) | 0.33% | — | Vmware Spring Cloud Gateway | 27/8/2026 | 10/9/2026 | Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier | |
| Analizada | Crítica (9.8) | 0.55% | — | Vmware Spring Cloud Config | 26/8/2026 | 4/9/2026 | Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from 4.0.0 through 4.2.8, and through 3.1.14. | |
| Analizada | Alta (8.1) | 0.22% | — | Vmware Spring Cloud Config | 26/8/2026 | 4/9/2026 | The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14… | |
| Analizada | Alta (8.2) | 0.52% | — | Microsoft Azure Spring Cloud | 14/7/2026 | 24/7/2026 | Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.46% | — | Broadcom Spring Cloud Sleuth | 15/6/2026 | 17/6/2026 | In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled.… | |
| Analizada | Alta (8.6) | 0.22% | — | Vmware Spring Cloud Gateway | 15/6/2026 | 1/10/2026 | Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway… | |
| Analizada | Media (6.5) | 0.28% | — | Vmware Spring Cloud Function | 1/6/2026 | 22/7/2026 | OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Spring Cloud Function 4.2.x: versions prior to 4.2.6 Spring Cloud Function… | |
| Analizada | Media (6.5) | 0.28% | — | Vmware Spring Cloud Function | 1/6/2026 | 22/7/2026 | Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Spring Cloud Function 4.2.x: versions prior to 4.2.6 Spring Cloud Function 4.3.x:… |