Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3953 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.3) | 0.36% | — | Parseplatform Parse-server | 18/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.15 and 8.6.41, an attacker who is allowed to upload files can bypass the file extension filter by appending a MIME parameter (e.g. `;charset=utf-8`) to the `Content-Type` header. This causes the… | |
| Modificada | Media (5.8) | 0.39% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 18/3/2026 | 17/6/2026 | A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result,… | |
| Aplazada | Media (5.5) | 0.41% | — | Tiandy Easy7 Integrated Management PlatformAI | 17/3/2026 | 17/6/2026 | A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an unknown function of the file /rest/preSetTemplate/getRecByTemplateId. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.5) | 0.41% | — | Tiandy Easy7 Integrated Management PlatformAI | 17/3/2026 | 17/6/2026 | A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown function of the file /rest/devStatus/getDevDetailedInfo of the component Endpoint. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Tiandy Easy7 Integrated Management PlatformAI | 17/3/2026 | 17/6/2026 | A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an unknown function of the file /rest/devStatus/queryResources of the component Endpoint. Performing a manipulation of the argument areaId results in sql injection. The attack can be initiated remotely.… | |
| Aplazada | Media (5.5) | 0.41% | — | Tiandy Integrated Management PlatformAI | 16/3/2026 | 17/6/2026 | A vulnerability was determined in Tiandy Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /rest/user/getAuthorityByUserId. Executing a manipulation of the argument userId can lead to sql injection. The attack may be launched remotely. The exploit has been publicly… | |
| Aplazada | Media (5.5) | 0.47% | — | Tiandy Easy7 Integrated Management PlatformAI | 16/3/2026 | 17/6/2026 | A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This affects an unknown part of the file /rest/file/uploadLedImage of the component Endpoint. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and… | |
| Aplazada | Media (5.5) | 0.51% | — | Symantec Management PlatformAI | 16/3/2026 | 17/6/2026 | A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /SetWebpagePic.jsp. The manipulation of the argument targetPath/Suffix leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.68% | — | Tiandy Easy7 Integrated Management PlatformAI | 16/3/2026 | 17/6/2026 | A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of the file /WebService/UpdateLocalDevInfo.jsp of the component Device Identifier Handler. Such manipulation of the argument username/password leads to missing authentication. The attack can be… | |
| Modificada | Alta (7.1) | 0.19% | — | GNU BinutilsRedhat Openshift Container PlatformRedhat Enterprise Linux | 16/3/2026 | 1/9/2026 | A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure… | |
| Modificada | Alta (7.1) | 0.19% | — | GNU BinutilsRedhat Openshift Container PlatformRedhat Enterprise Linux | 16/3/2026 | 1/9/2026 | A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially… | |
| Analizada | Media (6.9) | 0.47% | — | Parseplatform Parse-server | 16/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the GraphQL WebSocket endpoint for subscriptions does not pass requests through the Express middleware chain that enforces authentication, introspection control, and query… | |
| Analizada | Media (6.3) | 0.40% | — | Parseplatform Parse-server | 12/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.13 and 8.6.39, the OAuth2 authentication adapter does not correctly validate app IDs when appidField and appIds are configured. During app ID validation, a malformed value is sent to the token… | |
| Analizada | Crítica (9.3) | 0.92% | — | Parseplatform Parse-server | 12/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider that does not validate the format of the user identifier (e.g.… | |
| Analizada | Crítica (9.1) | 0.38% | — | Parseplatform Parse-server | 12/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singleton instance that is reused directly across all OAuth2 provider configurations. Under concurrent authentication… | |
| Analizada | Media (5.1) | 0.33% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.10 and 8.6.36, an attacker with access to the master key can inject malicious SQL via crafted field names used in query constraints when Parse Server is configured with PostgreSQL as the… | |
| Analizada | Media (6.9) | 0.49% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.9 and 8.6.35, an attacker can exploit LiveQuery subscriptions to infer the values of protected fields without directly receiving them. By subscribing with a WHERE clause that references a… | |
| Analizada | Media (6.3) | 0.40% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 and 9.6.0-alpha.8, the email verification endpoint (/verificationEmailRequest) returns distinct error responses depending on whether an email address belongs to an existing user, is already verified,… | |
| Analizada | Alta (8.2) | 0.52% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.7 and 8.6.33, when multi-factor authentication (MFA) via TOTP is enabled for a user account, Parse Server generates two single-use recovery codes. These codes are intended as a fallback when the… | |
| Analizada | Alta (8.7) | 0.47% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypassed using dot-notation in query WHERE clauses and sort parameters. An attacker can use dot-notation to query or sort by… | |
| Analizada | Crítica (9.3) | 0.54% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., stats.counter). The… | |
| Analizada | Media (6.3) | 0.33% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.4 and 8.6.30, an attacker can upload a file with a file extension or content type that is not blocked by the default configuration of the Parse Server fileUpload.fileExtensions option. The file… | |
| Analizada | Crítica (9.3) | 0.54% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., stats.counter). The amount value is interpolated directly… | |
| Analizada | Crítica (9.3) | 0.70% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination with the sort query parameter to inject SQL into the PostgreSQL database through an improper escaping of sub-field… | |
| Analizada | Media (5.4) | 0.15% | — | SplunkSplunk Cloud Platform | 11/3/2026 | 17/6/2026 | In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, and 10.0.2503.12, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve the Observability Cloud API access token through the Discover Splunk Observability… |