Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 86 respecto a la semana anterior
Críticas / altas1460▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)91▼ 420 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.74% | — | Apache Qpid Protonj2 | 5/8/2026 | 7/8/2026 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the… | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Protonj2 | 5/8/2026 | 7/8/2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Protonj2 | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the… | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the… | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Protonj2 | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Protonj2 | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-j | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. | |
| Aplazada | Alta (7.1) | 0.16% | — | Linux-gaming PortprotonqtAIGnome NetworkmanagerAI | 23/7/2026 | 23/7/2026 | An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe. | |
| Pendiente de análisis | Crítica (10) | 0.43% | — | Timeplus-io ProtonAI | 24/3/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src modules). This vulnerability is associated with program files inflate.C. This issue affects proton: before 1.6.16. | |
| Modificada | Alta (8.5) | 0.22% | — | Protonvpn | 13/1/2026 | 17/6/2026 | ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path by placing malicious executables in specific file system locations to gain elevated privileges during… | |
| Modificada | Alta (7.8) | 0.31% | — | Protonvpn | 22/7/2024 | 17/6/2026 | ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss. | |
| Modificada | Media (5.4) | 0.62% | — | Proton Project Proton | 20/5/2022 | 17/6/2026 | Proton v0.2.0 allows an attacker to create a malicious link inside a markdown file. When the victim clicks the link, the application opens the site in the current frame allowing an attacker to host JavaScript code in the malicious link in order to trigger an XSS attack. The 'nodeIntegration' configuration is set to on… | |
| Modificada | Alta (7.5) | 1.0% | — | Protonmail | 14/5/2021 | 17/6/2026 | ProtonMail Web Client is the official AngularJS web client for the ProtonMail secure email service. ProtonMail Web Client before version 3.16.60 has a regular expression denial-of-service vulnerability. This was fixed in commit 6687fb. There is a full report available in the referenced GHSL-2021-027. | |
| Modificada | Crítica (9.8) | 29% | — | Optergy EnterpriseOptergy Proton | 1/7/2019 | 17/6/2026 | Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root. | |
| Modificada | Alta (8.8) | 4.5% | — | Optergy EnterpriseOptergy Proton | 1/7/2019 | 17/6/2026 | Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF). |