Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.26% | — | Open-metadata OpenmetadataAI | 25/9/2026 | 25/9/2026 | OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to create or update EventSubscription can set webhook destinations to internal hosts, allowing the… | |
| Aplazada | Alta (8.5) | 0.55% | — | Open-metadata OpenmetadataAI | 26/8/2026 | 16/9/2026 | OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the assertion consumer servlet later formats… | |
| Aplazada | Alta (8.3) | 0.42% | — | Open-metadata OpenmetadataAI | 8/6/2026 | 23/7/2026 | OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a Database Service and receive, in the HTTP 201 response of POST /api/v1/automations/workflows, both the cleartext database password in request.connection.config.password and the… | |
| Analizada | Alta (7.6) | 0.36% | — | Open-metadata Openmetadata | 11/2/2026 | 17/6/2026 | OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This… | |
| Modificada | Alta (8.5) | 1.3% | — | Open-metadata Openmetadata | 8/1/2026 | 31/8/2026 | OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch. | |
| Analizada | Media (6.5) | 0.30% | — | Open-metadata Openmetadata | 8/8/2025 | 17/6/2026 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the DocStoreDAO interface. The entityType parameters can be used to build a SQL query. | |
| Analizada | Media (6.5) | 0.26% | — | Open-metadata Openmetadata | 8/8/2025 | 17/6/2026 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The supportedDataTypeParam parameter can be used to build a SQL query. | |
| Analizada | Media (6.5) | 0.33% | — | Open-metadata Openmetadata | 8/8/2025 | 17/6/2026 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The entityType parameter can be used to build a SQL query. | |
| Analizada | Alta (8.8) | 0.32% | — | Open-metadata Openmetadata | 8/8/2025 | 17/6/2026 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatform parameter can be used to build a SQL query. | |
| Analizada | Alta (8.8) | 0.61% | — | Open-metadata Openmetadata | 17/4/2025 | 17/6/2026 | OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query. | |
| Analizada | Alta (8.8) | 7.9% | — | Open-metadata Openmetadata | 15/3/2024 | 17/6/2026 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `CompiledRule::validateExpression` method evaluates an SpEL expression using an `StandardEvaluationContext`, allowing the expression to reach… | |
| Analizada | Alta (8.8) | 2.4% | — | Open-metadata Openmetadata | 15/3/2024 | 17/6/2026 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. Similarly to the GHSL-2023-250 issue, `AlertUtil::validateExpression` is also called from `EventSubscriptionRepository.prepare()`, which can lead… | |
| Analizada | Crítica (9.8) | 73% | — | Open-metadata Openmetadata | 15/3/2024 | 17/6/2026 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the API authentication by requiring and verifying JWT tokens. When a new request comes in, the request's path is checked… | |
| Analizada | Alta (8.8) | 46% | — | Open-metadata Openmetadata | 15/3/2024 | 17/6/2026 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `AlertUtil::validateExpression` method evaluates an SpEL expression using `getValue` which by default uses the `StandardEvaluationContext`,… | |
| Analizada | Alta (8.8) | 13% | — | Open-metadata Openmetadata | 15/3/2024 | 17/6/2026 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also called from `PolicyRepository.prepare`. `prepare()` is called from `EntityRepository.prepareInternal()`… |