Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.7) | — | — | Rabbitmq Java ClientAI | 6/10/2026 | 6/10/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.35.0, ConnectionFactoryConfigurator.load() includes the raw uri value in wrapped exceptions when AMQP URI parsing fails. Because the URI may contain a plaintext username and password,… | |
| Pendiente de análisis | Media (6) | — | — | Rabbitmq Java Client LibraryAI | 6/10/2026 | 6/10/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An… | |
| Pendiente de análisis | Media (4.9) | — | — | Rabbitmq Java ClientAI | 6/10/2026 | 6/10/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at… | |
| Pendiente de análisis | Alta (7.5) | 0.37% | — | IBM MQAIIBM MQ Java ClientAIIBM MQ JMS ClientAI | 18/9/2026 | 21/9/2026 | IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling. | |
| Pendiente de análisis | Alta (8.7) | 0.55% | — | Rabbitmq Java Client LibraryAI | 16/9/2026 | 24/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySize, frameMax) after Connection.Tune negotiation even though AMQP defines frameMax value zero as unlimited and… | |
| Pendiente de análisis | Alta (8.7) | 0.73% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F… | |
| Pendiente de análisis | Media (5.1) | 0.31% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) configure com.rabbitmq.client.TrustEverythingTrustManager and leave hostname… | |
| Pendiente de análisis | Media (6.3) | 0.52% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header whose remainingBodyBytes value is smaller… | |
| Pendiente de análisis | Ninguna (0) | 0.49% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java and NettyFrameHandlerFactory continue… | |
| Pendiente de análisis | Alta (8.7) | 0.73% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 18/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-declared contentLength below Integer.MAX_VALUE and allocate a byte array before… | |
| Pendiente de análisis | Alta (7.5) | 0.56% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 18/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted system.describe response and passes it through JSONUtil.tryFill, setJavaReturnType,… | |
| Analizada | Alta (8.2) | 0.43% | — | Appium Java-client | 28/7/2026 | 7/8/2026 | Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) is enabled, AppiumCommandExecutor.setDirectConnect() reads the directConnectHost, directConnectPort, and directConnectPath fields from the server's… | |
| Pendiente de análisis | Baja (2.4) | 0.35% | — | Kubernetes Java Client LibraryAI | 23/7/2026 | 23/7/2026 | A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false. | |
| Modificada | Alta (7.5) | 1.1% | — | Vmware Rabbitmq Java Client | 25/10/2023 | 17/6/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects. Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from DoS… | |
| Modificada | Crítica (9.8) | 1.8% | — | Aerospike Java Client | 4/8/2023 | 17/6/2026 | The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects that the client deserializes when it encounters them without further… | |
| Modificada | Alta (7.5) | 0.83% | — | Eclipse Paho Java Client | 11/9/2019 | 17/6/2026 | In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with incorrect information. | |
| Analizada | Media (5.9) | 1.2% | — | Pivotal Software Spring Advanced Message Queuing ProtocolVmware Rabbitmq Java Client | 14/9/2018 | 17/6/2026 | Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit. | |
| Modificada | Baja (2.1) | 0.40% | — | Linecontrol Java Client | 20/9/2005 | 16/6/2026 | AuthInfo.java in LineContol Java Client (jlc) before 0.8.1 stores sensitive information such as user passwords in log files. |