Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
184 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.9) | 0.41% | — | Osgeo Mapserver | 19/9/2025 | 17/6/2026 | MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive PropertyName is vulnerably to Boolean-based SQL injection. It seems like expression checking is bypassed by introducing double quote characters in the PropertyName. Allowing to manipulate backend database… | |
| Aplazada | Media (6.9) | 0.31% | — | Pilotgaea Technologies Oview MapserverAI | 15/9/2025 | 17/6/2026 | O'View MapServer developed by PilotGaea Technologies has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network. | |
| Analizada | Media (4.3) | 63% | ⚠ Explotación activa💥 Exploit | Wftpserver Wing FTP Server | 10/7/2025 | 17/6/2026 | loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. | |
| Analizada | Crítica (10) | 93% | ⚠ Explotación activa💥 Exploit | Wftpserver Wing FTP Server | 10/7/2025 | 17/6/2026 | In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code… | |
| Analizada | Media (6.6) | 5.1% | — | Wftpserver Wing FTP Server | 10/7/2025 | 17/6/2026 | In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default. The web application itself offers several legitimate ways to execute arbitrary system commands (i.e., through the web console or the task scheduler), and they are automatically… | |
| Analizada | Alta (8.8) | 0.46% | — | Wftpserver Wing FTP Server | 10/7/2025 | 17/6/2026 | Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker. | |
| Aplazada | Alta (8.7) | 0.43% | — | EspasynchttpserverAI | 27/6/2025 | 17/6/2026 | ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and including 3.7.8, a CRLF (Carriage Return Line Feed) injection vulnerability exists in the construction and output of HTTP headers within `AsyncWebHeader.cpp`. Unsanitized input allows… | |
| Analizada | Alta (7.5) | 1.0% | 💥 PoC | Wftpserver Wing FTP Server | 26/5/2025 | 17/6/2026 | A vulnerability has been found in Wing FTP Server up to 7.4.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Lua Admin Console. The manipulation leads to execution with unnecessary privileges. The attack can be launched remotely. The complexity of an attack is… | |
| Analizada | Media (4.3) | 0.33% | — | Fit2cloud Jumpserver | 31/3/2025 | 17/6/2026 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.8.0 and 3.10.18, an attacker with a low-privileged account can access the Kubernetes session feature and manipulate the kubeconfig file to redirect API requests to an external server controlled by the attacker.… | |
| Aplazada | Alta (7.5) | 0.38% | — | WampserverAI | 9/12/2024 | 17/6/2026 | A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized users could access sensitive information due to improper access control validation via PHP Info Page. This issue can lead to data leaks. | |
| Aplazada | Media (5.4) | 0.38% | — | Matrix Appservice-ircAI | 14/11/2024 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability which can lead to arbitrary IRC command execution as the bridge IRC bot. The vulnerability has been patched in matrix-appservice-irc… | |
| Modificada | Crítica (9.8) | 1.3% | — | Fit2cloud Jumpserver | 18/7/2024 | 17/6/2026 | JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploit the Ansible playbook to write arbitrary files, leading to remote code… | |
| Modificada | Crítica (9.1) | 0.86% | — | Fit2cloud Jumpserver | 18/7/2024 | 17/6/2026 | JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploit the ansible playbook to read arbitrary files in the celery container, leading… | |
| Modificada | Media (6.1) | 0.90% | 💥 Exploit | Wpserveur WPS Hide Login | 15/7/2024 | 17/6/2026 | The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page. | |
| Aplazada | Media (4.3) | 0.50% | — | Matrix Appservice-ircAI | 5/7/2024 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The fix for GHSA-wm4w-7h2q-3pf7 / CVE-2024-32000 included in matrix-appservice-irc 2.0.0 relied on the Matrix homeserver-provided timestamp to determine whether a user has access to the event they're replying to when determining whether… | |
| Modificada | Media (5.3) | 1.2% | 💥 Exploit | Wpserveur WPS Hide Login | 11/6/2024 | 17/6/2026 | The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by… | |
| Aplazada | Baja (3.7) | 0.30% | — | Wpserveur WPS Hide LoginAI | 4/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPServeur, NicolasKulka, wpformation WPS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPS Hide Login: from n/a through 1.9.11. | |
| Aplazada | Media (4.3) | 0.45% | — | Matrix Appservice-ircAI | 12/4/2024 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. matrix-appservice-irc before version 2.0.0 can be exploited to leak the truncated body of a message if a malicious user sends a Matrix reply to an event ID they don't have access to. As a precondition to the attack, the malicious user… | |
| Modificada | Crítica (9.9) | 5.9% | — | Fit2cloud Jumpserver | 29/3/2024 | 17/6/2026 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database access,… | |
| Modificada | Crítica (9.9) | 5.9% | — | Fit2cloud Jumpserver | 29/3/2024 | 17/6/2026 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database access, attackers… | |
| Analizada | Media (5.3) | 0.24% | — | Fit2cloud Jumpserver | 29/3/2024 | 17/6/2026 | JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability in the file manager's bulk transfer by manipulating job IDs to upload malicious files, potentially compromising the integrity and… | |
| Analizada | Media (5.3) | 0.29% | — | Fit2cloud Jumpserver | 29/3/2024 | 17/6/2026 | JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive information contained within playbook files if they manage to learn the playbook_id of another user. This breach of confidentiality can lead to information disclosure and… | |
| Analizada | Media (6.1) | 1.1% | 💥 Exploit | Fit2cloud Jumpserver | 20/2/2024 | 17/6/2026 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to construct malicious links, leading users to click on them, thereby facilitating phishing attacks or cross-site scripting attacks. Version 3.10.0… | |
| Modificada | Media (5.3) | 0.36% | — | PTC Kepware KepserverexPTC Thingworx Kepware ServerPTC Thingworx Industrial Connectivity | 10/1/2024 | 17/6/2026 | An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication. | |
| Modificada | Media (4.7) | 0.24% | — | PTC Kepware KepserverexPTC Thingworx Kepware ServerPTC Thingworx Industrial Connectivity | 10/1/2024 | 17/6/2026 | An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline. |