Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 86 respecto a la semana anterior
Críticas / altas1460▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)91▼ 420 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.20% | — | Khubbaib Mandrill WPAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in khubbaib Mandrill WP email-form-under-post allows Stored XSS.This issue affects Mandrill WP: from n/a through <= 1.0.5. | |
| Aplazada | Media (4.3) | 0.39% | — | Matt Miller Send Emails With MandrillAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Matt Miller Send Emails with Mandrill send-emails-with-mandrill allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Send Emails with Mandrill: from n/a through <= 1.4.1. | |
| Modificada | Alta (8.8) | 0.75% | — | Apache Drill | 24/7/2024 | 17/6/2026 | XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue. | |
| Modificada | Media (4.3) | 0.28% | — | Millermedia Mandrill | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Mandrill wpMandrill.This issue affects wpMandrill: from n/a through 1.33. | |
| Modificada | Alta (7.5) | 2.3% | — | Apache-airflow-providers-apache-drill | 11/8/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an opportunity to read files on the Airflow… | |
| Modificada | Alta (7.5) | 2.1% | — | Apache-airflow-providers-apache-drill | 7/4/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2. | |
| Modificada | Media (6.1) | 0.38% | — | Mediawiki Semantic Drilldown | 16/12/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in SemanticDrilldown Extension. Affected is the function printFilterLine of the file includes/specials/SDBrowseDataPage.php of the component GET Parameter Handler. The manipulation of the argument value leads to cross site scripting. It is possible to launch the… | |
| Modificada | Alta (7.5) | 11% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraApache Drill+14 | 30/7/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath. | |
| Modificada | Media (5.9) | 9.7% | — | Apache ActivemqApache DrillApache ZookeeperDebian Linux+6 | 23/5/2019 | 17/6/2026 | An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id… | |
| Modificada | Media (6.1) | 9.6% | — | Eclipse JettyDebian LinuxApache ActivemqApache Drill+3 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents. | |
| Modificada | Media (5.4) | 1.1% | — | Apache Drill | 18/12/2017 | 17/6/2026 | In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, malicious user may obtain this information from Profile… | |
| Modificada | Media (6.1) | 18% | — | Debian LinuxJqueryui Jquery UIFedoraproject FedoraNetapp Snapcenter+2 | 24/11/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option. | |
| Modificada | Media (4) | 1.1% | — | Thinkshout Mandrill | 3/12/2012 | 16/6/2026 | The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links by reading the logs in the Mandrill dashboard. |