Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
943 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | Fortinet FortiproxyFortinet FortiosFortinet Fortipam | 13/12/2023 | 17/6/2026 | A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiPAM versions 1.0.0 through 1.0.3 allows attacker to execute… | |
| Modificada | Media (5.4) | 2.2% | 💥 Exploit | Modcluster MOD Proxy ClusterRedhat Enterprise Linux | 12/12/2023 | 19/9/2026 | A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script… | |
| Modificada | Media (5.3) | 1.1% | — | Systematica Financial CalculatorSystematica FIX AdapterSystematica Http AdapterSystematica Mssql Messagebus Proxy+2 | 30/11/2023 | 17/6/2026 | Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote attackers to read arbitrary files via a full pathname in GET parameter "file" in URL. Also: affected components in same product - HTTP Adapter (up to v.1.8.0.15),… | |
| Modificada | Alta (8.2) | 1.5% | 💥 PoC | Haproxy | 28/11/2023 | 17/6/2026 | HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server. | |
| Modificada | Crítica (9.8) | 0.57% | — | Clastix Capsule-proxy | 24/11/2023 | 17/6/2026 | capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is based on a missing check if the user is authenticated based on the `TokenReview` result. All the clusters running with the `anonymous-auth` Kubernetes API Server setting… | |
| Modificada | Alta (7.5) | 1.4% | — | F5 Big-ip NextF5 Big-ip Next Service Proxy FOR KubernetesF5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Local Traffic Manager+2 | 21/11/2023 | 17/6/2026 | The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute. | |
| Modificada | Media (6.5) | 1.3% | — | Fortinet FortiproxyFortinet Fortios | 14/11/2023 | 17/6/2026 | A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1, all versions, FortiProxy 1.0 all versions, FortiOS version 7.4.0, FortiOS version 7.2.0 through 7.2.5, FortiOS version 7.0.0… | |
| Modificada | Media (6.7) | 0.17% | — | Fortinet FortiproxyFortinet Fortios | 14/11/2023 | 17/6/2026 | An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the filesystem integrity check… | |
| Modificada | Media (4.3) | 0.41% | — | Clastix CapsuleClastix Capsule-proxy | 6/11/2023 | 17/6/2026 | capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used by `capsule-proxy` gives ServiceAccount tenant owners the right to list Namespaces of other tenants backed by the same owner kind and name. For example consider two tenants `solar` and `wind`.… | |
| Analizada | Alta (8.8) | 2.5% | — | Kubernetes CSI Proxy | 3/11/2023 | 17/6/2026 | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache ActivemqApache Activemq Legacy Openwire ModuleDebian LinuxNetapp E-series Santricity Unified Manager+2 | 27/10/2023 | 17/6/2026 | The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or… | |
| Modificada | Alta (8.8) | 1.5% | — | Mtproto MT Proto Proxy | 10/10/2023 | 17/6/2026 | In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access an improperly secured default installation without authenticating and achieve remote command execution ability. | |
| Modificada | Media (5.3) | 1.0% | — | Fortinet FortiproxyFortinet Fortios | 10/10/2023 | 17/6/2026 | A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.4) | 0.38% | — | F5 Big-ip Next Service Proxy FOR Kubernetes | 10/10/2023 | 17/6/2026 | The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only exposed when ssh debug is enabled. Note:… | |
| Modificada | Alta (7.5) | 0.54% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+16 | 10/10/2023 | 17/6/2026 | When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical… | |
| Modificada | Crítica (9.8) | 1.4% | — | Withsecure F-secure Policy ManagerWithsecure Policy Manager Proxy | 22/9/2023 | 17/6/2026 | Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend). This affects WithSecure Policy Manager 15 and Policy Manager Proxy 15. | |
| Modificada | Media (5.4) | 1.3% | — | Fortinet FortiproxyFortinet Fortios | 13/9/2023 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14 GUI may allow an authenticated attacker to trigger… | |
| Modificada | Media (5.5) | 0.19% | — | IBM Sterling External Authentication ServerIBM Sterling Secure Proxy | 5/9/2023 | 17/6/2026 | IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585. | |
| Modificada | Media (5.5) | 0.38% | 💥 PoC | Zscaler Proxy | 31/8/2023 | 17/6/2026 | Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file download/upload restrictions. | |
| Modificada | Alta (7.2) | 2.1% | — | Haproxy | 10/8/2023 | 17/6/2026 | HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an… | |
| Modificada | Crítica (9.8) | 2.1% | — | Fortinet FortiproxyFortinet Fortios | 26/7/2023 | 17/6/2026 | A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or… | |
| Modificada | Media (5.3) | 0.70% | — | Envoyproxy Envoy | 25/7/2023 | 17/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Envoy allows mixed-case schemes in HTTP/2, however, some internal scheme checks are case-sensitive. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, this can lead to the rejection of requests with mixed-case schemes… | |
| Modificada | Alta (7.5) | 0.66% | — | Envoyproxy Envoy | 25/7/2023 | 17/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, the CORS filter will segfault and crash Envoy when the `origin` header is removed and deleted between `decodeHeaders`and `encodeHeaders`. Versions 1.27.0, 1.26.4,… | |
| Modificada | Media (6.5) | 0.89% | — | Envoyproxy Envoy | 25/7/2023 | 17/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, gRPC access loggers using listener's global scope can cause a `use-after-free` crash when the listener is drained. Versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12… |