Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.35% | — | Alibaba Qwen-agentAIGradioAI | 28/8/2026 | 23/9/2026 | Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal… | |
| Aplazada | Media (6.9) | 0.58% | — | Alibaba Fusion NextAI | 24/8/2026 | 24/8/2026 | A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype… | |
| Aplazada | Baja (2.1) | 0.37% | — | Aliyun Alibabacloud-dataworks-mcp-serverAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched… | |
| Aplazada | Media (5.8) | 0.40% | — | Alibabacloud RDS Openapi MCP ServerAI | 28/7/2026 | 28/7/2026 | Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default. | |
| Aplazada | Crítica (9) | 0.66% | — | Alibaba FastjsonAI | 23/7/2026 | 23/7/2026 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required. | |
| Aplazada | Baja (2.1) | 0.41% | — | Changmingxie Tcc-transactionAIAlibaba FastjsonAI | 25/5/2026 | 23/7/2026 | A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not… | |
| Aplazada | Alta (7.5) | 0.50% | — | Meari IOT CloudAIAlibaba OSSAI | 11/5/2026 | 17/6/2026 | In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected operational windows. | |
| Aplazada | Crítica (9.4) | 0.22% | — | Solax CloudAIAlibabacloud Alibaba CloudAI | 12/2/2026 | 17/6/2026 | The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.solaxcloud.com, TCP 8883). This allows attackers in a man-in-the-middle position to act as the legitimate MQTT server and issue arbitrary commands to devices. | |
| Aplazada | Crítica (10) | 0.77% | — | Alibaba FastjsonAI | 9/1/2026 | 15/7/2026 | Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-supplied payload… | |
| Aplazada | Crítica (10) | 19% | — | Hikvision Integrated Security Management PlatformAIAlibaba FastjsonAI | 2/7/2025 | 17/6/2026 | An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger… | |
| Aplazada | Media (4.7) | 0.21% | — | Ecovacs HomeAIAlibaba Object Storage ServiceAI | 23/5/2025 | 17/6/2026 | Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure. | |
| Modificada | Alta (7.5) | 0.80% | — | Alibaba Tengine | 22/8/2023 | 17/6/2026 | The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests. | |
| Modificada | Alta (8.8) | 1.3% | — | Alibabacloud Nacos Spring Project | 21/8/2023 | 17/6/2026 | An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component. | |
| Modificada | Alta (8.8) | 7.5% | — | Alibaba Nacos | 5/7/2022 | 17/6/2026 | An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login. | |
| Modificada | Crítica (9.8) | 19% | — | Alibaba FastjsonOracle Communications Cloud Native Core Unified Data Repository | 10/6/2022 | 17/6/2026 | The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable… | |
| Modificada | Crítica (9.8) | 3.9% | — | Alibabagroup One-java-agent | 1/5/2022 | 17/6/2026 | All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable files and either invoke them remotely or… | |
| Modificada | Media (6.1) | 0.83% | — | Alibaba Nacos | 11/3/2022 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters. | |
| Modificada | Alta (7.5) | 1.5% | — | Alibaba Druid | 3/11/2021 | 17/6/2026 | In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal. | |
| Modificada | Alta (7.5) | 66% | — | Alibaba Nacos | 27/4/2021 | 17/6/2026 | Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove endpoint is properly protected with the… | |
| Modificada | Crítica (9.8) | 83% | — | Alibaba Nacos | 27/4/2021 | 17/6/2026 | Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that enables Nacos… | |
| Modificada | Media (5.3) | 1.4% | — | Alibaba Nacos | 30/9/2020 | 17/6/2026 | Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details interface. Then other Nacos service names can be accessed through the service list interface. Service details can then be accessed when not logged in.… | |
| Modificada | Crítica (9.8) | 39% | — | Alibaba FastjsonPippo | 23/10/2018 | 17/6/2026 | parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in… | |
| Modificada | Media (5.4) | 0.66% | — | Alibaba Clone Script Project Alibaba Clone Script | 23/2/2018 | 17/6/2026 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Alibaba Clone Script 1.0.2 via a profile parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Alibaba | 20/9/2014 | 17/6/2026 | The alibaba (aka com.alibaba.wireless) application 4.1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 0.91% | — | Alibabaclone Alibaba Clone B2B | 27/9/2011 | 16/6/2026 | SQL injection vulnerability in countrydetails.php in Alibaba Clone B2B 3.4 allows remote attackers to execute arbitrary SQL commands via the es_id parameter. |