Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.23% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow belonging to that project through a sub-workflow task. The system does not properly verify whether the user has… | |
| Aplazada | Media (5.3) | 0.35% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafted request containing a percent-encoded path, a remote unauthenticated… | |
| Aplazada | Media (6.5) | 0.15% | — | Apache DolphinschedulerAI | 29/9/2026 | 1/10/2026 | A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticated user who does not have permission to access a specific project can… | |
| Aplazada | Media (4.3) | 0.18% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this… | |
| Aplazada | Media (4.3) | 0.18% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects. This issue affects… | |
| Aplazada | Alta (8.8) | 0.50% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as… | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields… | |
| Pendiente de análisis | Alta (8.1) | 0.23% | — | Apache DolphinschedulerAI | 24/9/2026 | 24/9/2026 | A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are… | |
| Analizada | Alta (8.8) | 0.58% | — | Apache Dolphinscheduler | 25/8/2026 | 28/9/2026 | General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Modificada | Media (6.5) | 0.55% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Modificada | Media (6.5) | 0.49% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue. | |
| Analizada | Media (4.9) | 0.54% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue. | |
| Modificada | Crítica (9.1) | 0.55% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Modificada | Crítica (9.8) | 0.66% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Pendiente de análisis | Media (6.5) | 0.16% | — | KDE DolphinAI | 28/4/2026 | 17/6/2026 | KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of the FileManager1 protocol allows the path given to be any type of file, including scripts or executables. (By default,… | |
| Analizada | Alta (8.1) | 0.45% | — | Apache Dolphinscheduler | 24/4/2026 | 17/6/2026 | Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1. Users are recommended to upgrade to version 3.4.1,… | |
| Analizada | Media (6.3) | 0.54% | — | Apache Dolphinscheduler | 24/4/2026 | 30/9/2026 | Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler: Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious class type into it, and… | |
| Analizada | Alta (7.5) | 0.52% | — | Apache Dolphinscheduler | 9/4/2026 | 30/9/2026 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthorized actors to access sensitive information, including database credentials. This issue affects Apache DolphinScheduler versions 3.1.*. Users are recommended to upgrade… | |
| Modificada | Crítica (9.8) | 0.52% | — | Apache Dolphinscheduler | 3/9/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue. | |
| Modificada | Alta (8.8) | 0.51% | — | Apache Dolphinscheduler | 3/9/2025 | 17/6/2026 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue. | |
| Analizada | Crítica (9.8) | 2.1% | — | Apache Dolphinscheduler | 20/8/2024 | 17/6/2026 | Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue. | |
| Modificada | Alta (7.5) | 0.72% | — | Corydolphin Flask-cors | 18/8/2024 | 17/6/2026 | A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to… | |
| Modificada | Alta (8.1) | 6.0% | — | Apache Dolphinscheduler | 12/8/2024 | 17/6/2026 | File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to version 3.2.2, which fixes the issue. | |
| Analizada | Alta (8.8) | 1.2% | — | Apache Dolphinscheduler | 12/8/2024 | 17/6/2026 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2. | |
| Modificada | Media (5.3) | 0.58% | — | Corydolphin Flask-cors | 19/4/2024 | 17/6/2026 | corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in the request path. This vulnerability allows attackers to corrupt log files, potentially covering… |