Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
927 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.3) | 0.59% | — | PCP PmproxyAI | 30/7/2026 | 1/10/2026 | An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover. | |
| Pendiente de análisis | Alta (7.2) | 1.1% | — | Heimdall Data Database ProxyAI | 29/7/2026 | 30/7/2026 | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within… | |
| Aplazada | Alta (7.5) | 0.55% | — | Artica ProxyAI | 28/7/2026 | 30/7/2026 | Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior to authentication. Attackers can pre-set a controlled session… | |
| Pendiente de análisis | Alta (8.5) | 0.53% | — | Openshift Oauth-proxyAI | 28/7/2026 | 21/9/2026 | A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated… | |
| Aplazada | Alta (7.5) | 0.57% | — | Facebook ProxygenAI | 23/7/2026 | 23/7/2026 | Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory… | |
| Analizada | Crítica (10) | 0.43% | — | Oracle Http ServerOracle Weblogic Server Proxy Plug-in | 21/7/2026 | 5/8/2026 | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Http ServerOracle Weblogic Server Proxy Plug-in | 21/7/2026 | 5/8/2026 | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access… | |
| Analizada | Media (4.8) | 0.48% | — | HaproxyHaproxy AlohaHaproxy Enterprise | 20/7/2026 | 25/8/2026 | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. | |
| Analizada | Baja (3.7) | 0.55% | — | HaproxyHaproxy AlohaHaproxy Enterprise | 20/7/2026 | 25/8/2026 | HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. | |
| Pendiente de análisis | Crítica (9.4) | 0.92% | — | Konnectivity Proxy ServerAI | 20/7/2026 | 14/9/2026 | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could… | |
| Analizada | Crítica (10) | 0.44% | — | Fastify/http-proxy | 18/7/2026 | 28/7/2026 | Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encoded form, and the prefix-rewrite step uses a literal string replace against the… | |
| Analizada | Crítica (10) | 0.50% | — | Fastify/http-proxy | 18/7/2026 | 28/7/2026 | Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapses dot segments, so… | |
| Aplazada | Media (5.3) | 0.39% | — | Fense Proxy VPN BlockerAI | 17/7/2026 | 21/7/2026 | The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_*… | |
| Analizada | Alta (8.7) | 0.57% | — | F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Next Service Proxy FOR Kubernetes | 15/7/2026 | 6/8/2026 | When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a… | |
| Modificada | Media (4.3) | 0.31% | — | Fortinet FortiproxyFortinet Fortios | 14/7/2026 | 11/8/2026 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow… | |
| Modificada | Media (5.5) | 0.25% | — | Fortinet FortiproxyFortinet FortiosFortinet Fortipam | 14/7/2026 | 11/8/2026 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions,… | |
| Modificada | Media (6.6) | 0.67% | — | Fortinet FortiproxyFortinet FortiosFortinet Fortipam | 14/7/2026 | 11/8/2026 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all… | |
| Modificada | Media (6.1) | 0.39% | — | Fortinet FortiproxyFortinet FortiosFortinet Fortipam | 14/7/2026 | 11/8/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions,… | |
| Modificada | Media (4.3) | 0.37% | — | Fortinet FortiproxyFortinet Fortios | 14/7/2026 | 29/9/2026 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow… | |
| Modificada | Media (4.3) | 0.27% | — | Fortinet FortiproxyFortinet Fortios | 14/7/2026 | 29/9/2026 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow… | |
| Modificada | Media (4.3) | 0.38% | — | Fortinet FortiproxyFortinet Fortios | 14/7/2026 | 29/9/2026 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted… | |
| Aplazada | Alta (7.1) | 0.25% | — | Proxy & VPN BlockerAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy & VPN Blocker Proxy & VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy & VPN Blocker: from n/a through <= 3.5.8. | |
| Modificada | Media (5.9) | 0.58% | — | Envoyproxy Envoy | 26/6/2026 | 8/7/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (envoy.filters.http.oauth2) can leave an in-flight async token exchange attached to a downstream stream that has already been torn down. A late AsyncClient completion can… | |
| Modificada | Alta (7.5) | 0.66% | — | Envoyproxy Envoy | 26/6/2026 | 15/7/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIRST, it's possible to crash Envoy when the specified host header is… | |
| Analizada | Media (5.9) | 0.39% | — | Envoyproxy Envoy | 26/6/2026 | 29/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5, and 1.38.3, a Use-After-Free (UAF) vulnerability leading to a sudden segmentation fault exists in Envoy's ext_authz HTTP filter when processing per-route authorization overrides concurrently with… |