Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
8466 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.44% | — | LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+7 | 21/7/2026 | 22/9/2026 | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. | |
| Modificada | Media (5.9) | 0.10% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. | |
| Modificada | Media (6.5) | 0.57% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. | |
| Modificada | Media (6.5) | 0.73% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. | |
| Analizada | Media (5.3) | 0.49% | — | LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+7 | 21/7/2026 | 22/9/2026 | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory. | |
| Analizada | Alta (7.3) | 0.17% | — | LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+7 | 21/7/2026 | 22/9/2026 | A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible… | |
| Analizada | Media (4.8) | 0.48% | — | HaproxyHaproxy AlohaHaproxy Enterprise | 20/7/2026 | 25/8/2026 | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. | |
| Analizada | Baja (3.7) | 0.55% | — | HaproxyHaproxy AlohaHaproxy Enterprise | 20/7/2026 | 25/8/2026 | HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. | |
| Modificada | Media (5.4) | 0.39% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 17/7/2026 | 16/9/2026 | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that… | |
| Aplazada | Crítica (9.1) | 0.44% | — | Vimesoft Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Crítica (9.4) | 0.46% | — | Vimesoft Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Vimesoft Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Alta (7.5) | 0.52% | — | Vimesoft INC Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Media (5.3) | 0.45% | — | Github Enterprise ServerAI | 17/7/2026 | 17/7/2026 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch names, commit SHAs, commit messages, and… | |
| Aplazada | Alta (8.6) | 0.75% | — | Github Enterprise ServerAI | 17/7/2026 | 17/7/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the path validation did not check the… | |
| Aplazada | Media (5.7) | 0.64% | — | Github Enterprise ServerAI | 17/7/2026 | 17/7/2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the configuration file was parsed without a nesting… | |
| Analizada | Crítica (10) | 0.63% | — | Jupyter Enterprise Gateway | 16/7/2026 | 5/8/2026 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the server interpolates untrusted environment variables (e.g., KERNEL_XXX) into Kubernetes manifests without YAML-aware escaping, enabling YAML… | |
| Analizada | Crítica (10) | 0.77% | — | Jupyter Enterprise Gateway | 16/7/2026 | 5/8/2026 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to 3.3.0, the environment variables (KERNEL_XXX) used during the rendering of the Kubernetes manifest are vulnerable to Server Side… | |
| Analizada | Crítica (9.8) | 0.71% | — | Jupyter Enterprise Gateway | 16/7/2026 | 5/8/2026 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior to 3.3.0 have a prohibited UID and GID feature that by default prevents launching kernels with UID or GID 0 (root), and this restriction can… | |
| Modificada | Baja (2.7) | 0.35% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 16/7/2026 | 16/9/2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to… | |
| Aplazada | Media (6.5) | 0.49% | — | Logicaldoc EnterpriseAI | 16/7/2026 | 5/10/2026 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files outside the designated directories. | |
| Aplazada | Alta (8.8) | 0.51% | — | Logicaldoc EnterpriseAI | 16/7/2026 | 5/10/2026 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input. | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Spotfire EnterpriseAISpotfire Enterprise With External ConsumersAISpotfire ON KubernetesAI | 14/7/2026 | 15/7/2026 | Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Server modules). This issue affects Spotfire Enterprise: through 14.0.12, through 14.4.2, through 14.5.0, through 14.6.1,… | |
| Pendiente de análisis | Media (6.1) | 0.29% | — | SAP Netweaver Enterprise PortalAI | 14/7/2026 | 14/7/2026 | SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user… | |
| Aplazada | Alta (7.3) | 0.34% | — | Logicaldoc EnterpriseAI | 13/7/2026 | 13/7/2026 | LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating input parameters to trigger a server-side request to an attacker-controlled host. |