Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 334 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.4)0.63%—Amazon Athena Query FederationAIAmazon NeptuneAIAmazon AthenaAIAmazon LambdaAI21/8/202627/8/2026
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.
Pendiente de análisisAlta (7.1)0.51%—Amazon AthenaAIAmazon Athena Federated QueryAIAmazon Secrets ManagerAI20/8/202625/8/2026
Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at…
AplazadaCrítica (9.3)0.77%—PyathenaAI2/8/202624/9/2026
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather…
Pendiente de análisisMedia (6.1)0.59%—Amazon Aws-athena-query-federationAI17/7/202620/7/2026
Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. Improper…
AnalizadaAlta (7.3)1.1%—Amazon Athena Odbc3/4/202624/7/2026
OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded by the driver during a local user-initiated connection. To remediate this issue,…
AnalizadaAlta (8.7)0.68%—Amazon Athena Odbc3/4/202624/7/2026
Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. To remediate this issue, users should…
AnalizadaCrítica (9.1)0.74%—Amazon Athena Odbc3/4/202624/7/2026
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-based authentication flows. To remediate this issue, users…
AnalizadaCrítica (9.1)0.36%—Amazon Athena Odbc3/4/202624/7/2026
Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to…
AnalizadaAlta (7.1)0.51%—Amazon Athena Odbc3/4/202624/7/2026
Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data that is processed by the driver during query operations. To remediate this issue, users should upgrade to version 2.1.0.0.
AnalizadaAlta (7.3)0.33%—Amazon Athena Odbc3/4/202624/7/2026
Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters that are processed by the driver during user-initiated…
AplazadaAlta (7.1)0.29%—Foreverpinetree ThenaAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree TheNa thena allows Reflected XSS.This issue affects TheNa: from n/a through <= 1.5.5.
AplazadaMedia (5.1)0.30%—Botble TranspAIBotble AthenaAIBotble MartfuryAIBotble HomzenAI20/1/202617/6/2026
HTML injection vulnerability in multiple Botble products such as TransP, Athena, Martfury, and Homzen, consisting of an HTML injection due to a lack of proper validation of user input by sending a request to '/search' using the 'q' parameter.
AplazadaAlta (8.6)0.20%—RathenaAIRathena FluxcpAI29/10/202517/6/2026
FluxCP is a web-based Control Panel for rAthena servers written in PHP. A critical Cross-Site Request Forgery (CSRF) vulnerability exists in the FluxCP-based website template used by multiple rAthena/Ragnarok servers. State-changing POST endpoints accept browser-initiated requests that are authorized solely by the…
AnalizadaAlta (7.5)0.37%—Rathena13/10/202517/6/2026
rAthena is an open-source cross-platform MMORPG server. A use-after-free vulnerability exists in the RODEX functionality of rAthena's map-server in versions prior to commit af2f3ba. An unauthenticated attacker can exploit this vulnerability via a specific attacking scenario to cause a denial of service by crashing the…
AnalizadaCrítica (9.1)0.30%—Rathena9/9/202517/6/2026
rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0cc348b are missing a bound check in `chclif_parse_moveCharSlot` that can result in reading and writing out of bounds using input from the user. The problem has been fixed in commit 0cc348b.
AnalizadaCrítica (9.8)0.36%—Rathena9/9/202517/6/2026
rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0d89ae0 have a SQL Injection in the PartyBooking component via `WorldName` parameter. Commit 0d89ae0 fixes the issue.
AnalizadaCrítica (9.8)0.88%—Rathena9/9/202517/6/2026
rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 2f5248b have a heap-based buffer overflow in the login server, remote attacker to overwrite adjacent session fields by sending a crafted `CA_SSO_LOGIN_REQ` with an oversized token length.…
AnalizadaMedia (6.1)0.28%—Rathena Fluxcp16/9/202417/6/2026
FluxCP is a web-based Control Panel for rAthena servers written in PHP. A javascript injection is possible via venders/buyers list pages and shop names, that are currently not sanitized. This allows executing arbitrary javascript code on the user's browser just by visiting the shop pages. As a result all logged in to…
ModificadaMedia (6.1)0.43%—Rathena Fluxcp12/12/202217/6/2026
A vulnerability was found in rAthena FluxCP. It has been classified as problematic. Affected is an unknown function of the file themes/default/servicedesk/view.php of the component Service Desk Image URL Handler. The manipulation of the argument sslink leads to cross site scripting. It is possible to launch the attack…
ModificadaCrítica (9.3)1.3%—Python Athena Stack Project Python Athena Stack11/7/202217/6/2026
The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (7.8)0.48%—Insightsoftware Magnitude Simba Amazon Athena Jdbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena JDBC Driver 2.0.25 through 2.0.28 may allow a local user to execute code. NOTE: this is different from CVE-2022-29971.
ModificadaAlta (7.8)0.37%—Insightsoftware Magnitude Simba Amazon Athena Odbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena ODBC Driver 1.1.1 through 1.1.x before 1.1.17 may allow a local user to execute arbitrary code.
ModificadaMedia (4.7)0.47%—Microchip Atmel ToolboxAthena-scs IdprotectCryptsoft S/A Idflex VTecsec Armored Card+13/10/201917/6/2026
Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue…
ModificadaAlta (7.5)3.3%—Oliver MAY Athena PHP Website Administration29/11/200516/6/2026
PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrary PHP code via a URL in the athena_dir parameter.
ModificadaAlta (7.5)29%—David Maciejak Athena WEB Registration31/12/200416/6/2026
athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass parameter.