Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
25.716 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (8.5) | — | — | Backstage Plugin Scaffolder Backend Module Bitbucket CloudAIBackstage Plugin Scaffolder Backend Module Bitbucket ServerAI | 6/10/2026 | 6/10/2026 | Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module-bitbucket-server, the Bitbucket pull-request Scaffolder actions did not sufficiently validate filesystem paths. An… | |
| Recibida | Media (6.5) | — | — | Backstage Plugin Catalog Backend Module Bitbucket ServerAI | 6/10/2026 | 6/10/2026 | Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server package is affected by inconsistent repository filtering in bitbucket server catalog event updates. Deployments using event-driven updates in the Bitbucket Server… | |
| Pendiente de análisis | Sin puntuar | — | — | Devolutions ServerAI | 6/10/2026 | 6/10/2026 | Authentication bypass in the Azure AD external login flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured login-session token exposed in a redirect URL. | |
| Pendiente de análisis | Alta (8.7) | — | — | Github Enterprise ServerAI | 6/10/2026 | 6/10/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed a repository contributor to cause the appliance to issue requests to attacker-controlled internal hosts, which could be chained to achieve remote code execution on the appliance. The secret scanning validator for… | |
| Pendiente de análisis | Sin puntuar | — | — | Devolutions ServerAI | 6/10/2026 | 6/10/2026 | Missing authorization in the global vault in Devolutions Server 2026.3.7.0 and earlier allows an authenticated user with only the global vault view permission to modify and delete global contact and folder entries. | |
| Pendiente de análisis | Media (6.8) | — | — | Devolutions ServerAI | 6/10/2026 | 6/10/2026 | Authentication bypass OAuth device authorization flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured device verification link by an authenticated victim. | |
| Pendiente de análisis | Media (6) | — | — | Github Enterprise ServerAI | 6/10/2026 | 6/10/2026 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository collaborator with write access to delete the current default branch through the GraphQL API and cause an attacker-controlled branch to become the new default. In repositories that required pull-request review but… | |
| Pendiente de análisis | Media (5.3) | — | — | Opentext Content ServerAI | 6/10/2026 | 6/10/2026 | Cross-site Scripting (XSS) in the Forums feature of OpenText Content Management Content Server could allow a bad actor to inject malicious code into a Forums web page. | |
| Aplazada | Alta (7.5) | 0.30% | — | Xserver MigratorAI | 6/10/2026 | 6/10/2026 | Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions. | |
| Aplazada | Media (4.8) | 0.19% | — | Joplin ServerAI | 5/10/2026 | 5/10/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts… | |
| Aplazada | Media (6.5) | 0.38% | — | K6 MCP ServerAI | 5/10/2026 | 6/10/2026 | A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that user's home directory (path traversal). The working-directory… | |
| Pendiente de análisis | Media (6.9) | 0.20% | — | Zabbix ServerAIZabbix ProxyAI | 5/10/2026 | 6/10/2026 | Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity. | |
| Pendiente de análisis | Baja (2.3) | 0.23% | — | Zabbix ServerAIZabbix ProxyAI | 5/10/2026 | 6/10/2026 | The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database. | |
| Pendiente de análisis | Media (6.9) | 0.24% | — | Zabbix ServerAI | 5/10/2026 | 6/10/2026 | The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator. | |
| Pendiente de análisis | Alta (8.8) | 0.50% | — | Microsoft Exchange ServerAI | 2/10/2026 | 6/10/2026 | Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. | |
| Aplazada | Alta (7) | 0.28% | — | Apache Traffic ServerAI | 2/10/2026 | 2/10/2026 | Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x… | |
| Aplazada | Media (5.5) | 0.29% | — | Modelcontextprotocol MCP Server FetchAIModelcontextprotocol MCP Server EverythingAI | 2/10/2026 | 6/10/2026 | A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack… | |
| Aplazada | Alta (7.6) | 0.29% | — | Office Powerpoint MCP ServerAI | 1/10/2026 | 2/10/2026 | Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or… | |
| Pendiente de análisis | Media (6.9) | 0.14% | — | Amazon Security Agent MCP ServerAI | 1/10/2026 | 1/10/2026 | An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan… | |
| Analizada | Alta (8.8) | 0.44% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces. | |
| Analizada | Media (5.3) | 0.59% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.3) | 0.48% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.… | |
| Analizada | Alta (8.1) | 0.41% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry… | |
| Analizada | Alta (7.5) | 0.32% | — | Apache Http Server | 1/10/2026 | 6/10/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.48% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version… |