Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
25.871 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.48% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version… | |
| Analizada | Alta (7.5) | 0.88% | 💥 PoC | Apache Http Server | 1/10/2026 | 5/10/2026 | Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname… | |
| Analizada | Alta (7.5) | 0.47% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.… | |
| Analizada | Crítica (9.8) | 0.52% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.50% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Media (5.3) | 0.53% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server:… | |
| Analizada | Crítica (9.8) | 0.60% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.61% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Crítica (9.8) | 0.56% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.50% | — | Apache Http Server | 1/10/2026 | 2/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.61% | — | Apache Http Server | 1/10/2026 | 6/10/2026 | Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck… | |
| Pendiente de análisis | Media (4.8) | 0.15% | — | Fortra Boks Server AgentAI | 1/10/2026 | 1/10/2026 | Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can… | |
| Analizada | Alta (7.5) | 0.39% | — | Apache Http Server | 1/10/2026 | 2/10/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.47% | — | Apache Http Server | 1/10/2026 | 2/10/2026 | NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Media (4.3) | 0.42% | — | Apache Http Server | 1/10/2026 | 6/10/2026 | A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue | |
| Analizada | Baja (3.7) | 0.47% | — | Apache Http Server | 1/10/2026 | 6/10/2026 | Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server:… | |
| Pendiente de análisis | Alta (7.1) | 0.26% | — | Octopus ServerAI | 1/10/2026 | 1/10/2026 | In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization. | |
| Aplazada | Crítica (9.3) | 0.33% | — | Genian NAC Ztna Policy ServerAI | 1/10/2026 | 1/10/2026 | Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions | |
| Pendiente de análisis | Crítica (9.4) | 0.26% | — | Litespeed WEB ServerAI | 30/9/2026 | 30/9/2026 | LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case." | |
| Aplazada | Media (6.5) | 0.13% | — | Dash10 Oauth ServerAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. | |
| Aplazada | Baja (2.1) | 1.1% | — | 0xshariq Github-mcp-serverAI | 30/9/2026 | 2/10/2026 | A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be… | |
| Aplazada | Media (5.9) | 0.19% | — | Mark3labs MCP Filesystem ServerAI | 29/9/2026 | 30/9/2026 | mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved… | |
| Aplazada | Crítica (9.8) | 0.75% | — | Altumcode 66uptimeAIAltumcode 66uptime Ping ServersAI | 29/9/2026 | 29/9/2026 | An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php | |
| Pendiente de análisis | Media (5.4) | 0.17% | — | Devolutions ServerAI | 29/9/2026 | 30/9/2026 | Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create, modify, and delete System Vault entries via a crafted API request. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Devolutions ServerAI | 29/9/2026 | 29/9/2026 | Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset. |