Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
25.714 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.52% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.50% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Media (5.3) | 0.53% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server:… | |
| Analizada | Crítica (9.8) | 0.60% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.61% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Crítica (9.8) | 0.56% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.50% | — | Apache Http Server | 1/10/2026 | 2/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.61% | — | Apache Http Server | 1/10/2026 | 6/10/2026 | Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck… | |
| Pendiente de análisis | Media (4.8) | 0.15% | — | Fortra Boks Server AgentAI | 1/10/2026 | 1/10/2026 | Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can… | |
| Analizada | Alta (7.5) | 0.39% | — | Apache Http Server | 1/10/2026 | 2/10/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.47% | — | Apache Http Server | 1/10/2026 | 2/10/2026 | NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Media (4.3) | 0.42% | — | Apache Http Server | 1/10/2026 | 6/10/2026 | A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue | |
| Analizada | Baja (3.7) | 0.47% | — | Apache Http Server | 1/10/2026 | 6/10/2026 | Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server:… | |
| Pendiente de análisis | Alta (7.1) | 0.26% | — | Octopus ServerAI | 1/10/2026 | 1/10/2026 | In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization. | |
| Aplazada | Crítica (9.3) | 0.33% | — | Genian NAC Ztna Policy ServerAI | 1/10/2026 | 1/10/2026 | Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions | |
| Pendiente de análisis | Crítica (9.4) | 0.26% | — | Litespeed WEB ServerAI | 30/9/2026 | 30/9/2026 | LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case." | |
| Aplazada | Media (6.5) | 0.13% | — | Dash10 Oauth ServerAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. | |
| Aplazada | Baja (2.1) | 1.1% | — | 0xshariq Github-mcp-serverAI | 30/9/2026 | 2/10/2026 | A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be… | |
| Aplazada | Media (5.9) | 0.19% | — | Mark3labs MCP Filesystem ServerAI | 29/9/2026 | 30/9/2026 | mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved… | |
| Aplazada | Crítica (9.8) | 0.75% | — | Altumcode 66uptimeAIAltumcode 66uptime Ping ServersAI | 29/9/2026 | 29/9/2026 | An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php | |
| Pendiente de análisis | Media (5.4) | 0.17% | — | Devolutions ServerAI | 29/9/2026 | 30/9/2026 | Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create, modify, and delete System Vault entries via a crafted API request. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Devolutions ServerAI | 29/9/2026 | 29/9/2026 | Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset. | |
| Pendiente de análisis | Alta (7.2) | 0.07% | — | Devolutions ServerAI | 29/9/2026 | 30/9/2026 | Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records. | |
| Pendiente de análisis | Media (5.4) | 0.17% | — | Devolutions ServerAI | 29/9/2026 | 29/9/2026 | Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to permanently delete or restore vault attachments via a crafted API request. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | Devolutions ServerAI | 29/9/2026 | 29/9/2026 | Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a crafted API request. |