Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

942 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.29%—Envoyproxy Gateway6/3/202517/6/2026
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. In all Envoy Gateway versions prior to 1.2.7 and 1.3.1 a default Envoy Proxy access log configuration is used. This format is vulnerable to log injection attacks. If the attacker uses a specially…
AnalizadaAlta (8.4)0.50%—Oxyno-zeta S3-proxy20/2/202517/6/2026
oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create malicious URLs that, when visited, inject scripts into the web application. This can lead to session hijacking or phishing attacks on a trusted domain, posing a…
AplazadaMedia (6.8)0.23%—Docker-proxyAI13/2/202517/6/2026
An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service.
AnalizadaMedia (5.1)0.47%—Lanproxy Project Lanproxy11/2/202517/6/2026
Directory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive information
AnalizadaAlta (8.1)7.2%⚠ Explotación activa💥 PoCFortinet FortiproxyFortinet Fortios11/2/20255/8/2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin…
ModificadaMedia (6.7)0.24%—Fortinet FortiosFortinet FortiswitchmanagerFortinet FortiproxyFortinet Fortipam11/2/202517/6/2026
A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.
AplazadaAlta (8.2)0.83%—Mitmproxy MitmwebAI6/2/202517/6/2026
mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmweb is a web-based interface for mitmproxy. In mitmweb 11.1.1 and below, a malicious client can use mitmweb's proxy server (bound to `*:8080` by default) to access mitmweb's internal API (bound to…
AnalizadaAlta (8.7)0.41%—F5 Big-ip Next Service Proxy FOR KubernetesF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+85/2/202517/6/2026
When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaMedia (6)0.55%—Org.gaul S3proxyAI3/2/202517/6/2026
org.gaul S3Proxy implements the S3 API and proxies requests. Users of the filesystem and filesystem-nio2 storage backends could unintentionally expose local files to users. This issue has been addressed in version 2.6.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
ModificadaMedia (5.4)0.27%—Proxymis Html5 Chat30/1/202517/6/2026
The HTML5 chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'HTML5CHAT' shortcode in all versions up to, and including, 1.07 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.26%—Redhat Openshift Service MeshAIEnvoyproxy EnvoyAI28/1/202517/6/2026
The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of sanitization can allow attackers to inject malicious payloads into service mesh logs, leading to log injection and…
AplazadaMedia (5.3)0.87%💥 ExploitEvilmartians ImgproxyAI27/1/202517/6/2026
imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose services on the local host. This vulnerability is fixed in 3.27.2.
AplazadaAlta (8.4)0.24%—Deepin Dde-api-proxyAI24/1/202517/6/2026
An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root. Specifically, dde-api-proxy runs as root and forwards messages from arbitrary local users to legacy D-Bus methods in the actual D-Bus services, and the actual D-Bus services don't know about…
AnalizadaAlta (7.1)0.42%—Envoyproxy Gateway23/1/202517/6/2026
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin…
ModificadaMedia (6.1)0.45%—Fortinet FortiadcFortinet FortiauthenticatorFortinet FortiddosFortinet Fortiddos-f+1022/1/202517/6/2026
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
AnalizadaCrítica (9.1)0.67%—IBM Sterling Secure Proxy19/1/202517/6/2026
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input.
AnalizadaCrítica (9.1)0.48%—IBM Sterling Secure Proxy19/1/202517/6/2026
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments.
AnalizadaCrítica (9.8)94%⚠ Explotación activa💥 ExploitFortinet FortiproxyFortinet Fortios14/1/20255/8/2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
AnalizadaMedia (5.8)0.78%—Fortinet FortiproxyFortinet Fortios14/1/202517/6/2026
An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 may allow a remote unauthenticated attacker to bypass the file filter via crafted HTTP headers.
AnalizadaCrítica (9.8)0.48%—Fortinet FortianalyzerFortinet Fortianalyzer CloudFortinet FortimanagerFortinet Fortimanager Cloud+214/1/202517/6/2026
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3,…
ModificadaCrítica (9.1)15%—Fortinet FortimanagerFortinet Fortimanager CloudFortinet FortiproxyFortinet Fortirecorder+314/1/20258/7/2026
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through 7.2.9, FortiOS 7.0.0 through 7.0.15,…
AplazadaAlta (7.1)0.34%—Greg Simple ProxyAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg – SiteOrigin Simple Proxy simple-proxy allows Reflected XSS.This issue affects Simple Proxy: from n/a through <= 1.0.
AnalizadaAlta (7.1)0.62%—Envoyproxy Envoy18/12/202417/6/2026
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no…
AnalizadaAlta (7.5)0.70%—Envoyproxy Envoy18/12/202417/6/2026
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request exists when `envoy.load_shed_points.http1_server_abort_dispatch` is configured. If `active_request` is nullptr, only onMessageBeginImpl() is called. However, the…
AnalizadaAlta (7.5)0.68%—Envoyproxy Envoy18/12/202417/6/2026
Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and 1.30.8. Users are advised to upgrade. Users unable to upgrade may disable…
Orbitaley — Vulnerabilidades