Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.74% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing… | |
| Analizada | Crítica (9.9) | 0.46% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database. | |
| Analizada | Crítica (9.1) | 0.46% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with… | |
| Analizada | Crítica (9.9) | 0.57% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized… | |
| Analizada | Alta (8.1) | 0.39% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is… | |
| Analizada | Alta (8.8) | 0.21% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security… | |
| Aplazada | Media (4.4) | 0.31% | — | Super Progressive WEB AppsAI | 5/8/2026 | 12/8/2026 | The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_settings[offline_message_txt]` setting in all versions up to, and including, 2.2.43. This is due to insufficient input sanitization and output escaping. The offline message value is stored without… | |
| Analizada | Alta (8) | 0.26% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Loadmaster+1 | 27/7/2026 | 11/8/2026 | A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their… | |
| Analizada | Alta (8) | 0.26% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially… | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface,… | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially… | |
| Analizada | Media (5.4) | 0.33% | — | Progress Moveit Transfer | 23/7/2026 | 30/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. | |
| Analizada | Crítica (9.8) | 0.37% | — | Progress Moveit Transfer | 23/7/2026 | 30/7/2026 | Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. | |
| Analizada | Crítica (9.8) | 0.37% | — | Progress Moveit Transfer | 23/7/2026 | 30/7/2026 | Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. | |
| Analizada | Crítica (9.8) | 0.60% | — | Progress Moveit Transfer | 23/7/2026 | 30/7/2026 | Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. | |
| Analizada | Media (6.5) | 0.35% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory. | |
| Analizada | Media (5.3) | 0.43% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion. | |
| Analizada | Media (6.5) | 0.42% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication… | |
| Analizada | Alta (8.1) | 0.50% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution. | |
| Analizada | Alta (7.5) | 0.36% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests. | |
| Analizada | Media (5.9) | 0.16% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation. | |
| Analizada | Alta (8.1) | 0.34% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation. | |
| Analizada | Alta (8.1) | 0.73% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution. | |
| Analizada | Alta (8.1) | 0.67% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution. |