Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

939 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (3.2)0.14%—Freedesktop Xdg-dbus-proxyAI18/9/202622/9/2026
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to…
Pendiente de análisisMedia (5.3)0.29%—Caddy Proxy ManagerAI17/9/202623/9/2026
Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration by default at /api/auth/sign-up/email, allowing an unauthenticated remote actor to create an active account with the user role without…
Pendiente de análisisCrítica (9.1)0.33%—Fastify Proxy-addrAI16/9/202617/9/2026
@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the…
Pendiente de análisisMedia (5.4)0.25%—Oracle Communications Cloud Native Core Security Edge Protection ProxyAI15/9/202622/9/2026
Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
Pendiente de análisisAlta (8.2)0.28%—Oracle Communications Cloud Native Core Security Edge Protection ProxyAI15/9/202618/9/2026
Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…
Pendiente de análisisAlta (7.1)0.25%—Oracle Communications Cloud Native Core Security Edge Protection ProxyAI15/9/202622/9/2026
Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication…
Pendiente de análisisAlta (7.5)0.16%—IBM Security Verify Identity Access Reverse ProxyAI15/9/202616/9/2026
IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
AplazadaAlta (7.5)0.72%—Vouch ProxyAI15/9/202630/9/2026
Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the value to make([]string, numParts) without checking that the value is positive or…
Pendiente de análisisCrítica (9.1)0.33%—Nodejs Proxy-addrAI15/9/202616/9/2026
proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct…
Pendiente de análisisMedia (5.4)0.31%—IBM Sterling Secure ProxyAI14/9/202616/9/2026
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup.
Pendiente de análisisMedia (4.3)0.36%—IBM Sterling Secure ProxyAI14/9/202616/9/2026
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass.
AplazadaMedia (6.9)0.47%—GoproxyAI14/9/202623/9/2026
goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic…
Pendiente de análisisMedia (6.5)0.71%—Envoy GatewayAIEnvoy ProxyAI14/9/202630/9/2026
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a nil authorization value when a namespace-scoped tenant creates a SecurityPolicy…
Pendiente de análisisMedia (6.4)0.41%—Envoyproxy Envoy GatewayAI14/9/202625/9/2026
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resource in another namespace without a matching Gateway API ReferenceGrant in the…
Pendiente de análisisMedia (6.5)0.71%—Envoyproxy Envoy GatewayAI14/9/202630/9/2026
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without limiting decompressed output when a tenant-controlled…
Pendiente de análisisCrítica (9.1)0.43%—Envoyproxy Envoy GatewayAIEnvoyproxy Envoy ProxyAI14/9/202630/9/2026
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redundant separators before is_critical_path evaluates Lua submitted through…
Pendiente de análisisMedia (6.5)0.71%—Envoyproxy Envoy GatewayAIEnvoyproxy Envoy ProxyAI14/9/202630/9/2026
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary…
Pendiente de análisisAlta (7.5)0.77%—HaproxyAI13/9/202622/9/2026
An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reach a backend over HTTP/1.1 using chunked transfer coding on a reused…
Pendiente de análisisAlta (7.5)0.57%—HPE Icewall Federation AgentAIHPE Icewall ProxyAI11/9/202611/9/2026
A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).
Pendiente de análisisAlta (8.1)0.25%—Fortinet FortiosAIFortinet FortiproxyAI8/9/202610/9/2026
A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>
Pendiente de análisisBaja (2.7)0.50%—Fortinet FortiosAIFortinet FortipamAIFortinet FortiproxyAI8/9/20268/9/2026
A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2…
AnalizadaAlta (7.5)0.74%—Fastify/http-proxy3/9/20269/9/2026
@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects…
AplazadaAlta (8.8)0.78%—Openwrt Luci-app-https-dns-proxyAI27/8/20261/9/2026
An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter
AplazadaCrítica (9.3)0.45%—Oauth2 ProxyAI24/8/202624/9/2026
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever…
AplazadaMedia (5.3)0.42%—Reverse ProxyAI23/8/202626/8/2026
Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands PATH_INFO to an application percent-decoded, so a %XX sequence in the client URL has become a raw byte by the time the proxy sees it. The proxy appends…