Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
25.717 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.2) | 0.07% | — | Devolutions ServerAI | 29/9/2026 | 30/9/2026 | Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records. | |
| Pendiente de análisis | Media (5.4) | 0.17% | — | Devolutions ServerAI | 29/9/2026 | 29/9/2026 | Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to permanently delete or restore vault attachments via a crafted API request. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | Devolutions ServerAI | 29/9/2026 | 29/9/2026 | Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a crafted API request. | |
| Pendiente de análisis | Alta (8.7) | 0.33% | — | Octopus ServerAI | 29/9/2026 | 29/9/2026 | In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process. | |
| Pendiente de análisis | Alta (7.7) | 0.26% | — | Bitwarden ServerAI | 29/9/2026 | 30/9/2026 | Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose… | |
| Pendiente de análisis | Media (6.8) | 0.15% | — | Dell Boot Optimized Server StorageAI | 28/9/2026 | 28/9/2026 | Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to… | |
| Pendiente de análisis | Media (4.6) | 0.13% | — | Zscaler MCP ServerAI | 28/9/2026 | 28/9/2026 | Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2. | |
| Aplazada | Media (5.5) | 0.45% | — | Privoce Vocechat ServerAI | 28/9/2026 | 28/9/2026 | A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be… | |
| Pendiente de análisis | Alta (7.4) | 0.21% | — | Parseplatform Parse ServerAI | 27/9/2026 | 30/9/2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, Weibo) verify the client's authorization code with the external provider on signup… | |
| Pendiente de análisis | Crítica (9.8) | 1.7% | — | HmailserverAI | 27/9/2026 | 29/9/2026 | Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with the privileges of the service account, via a password containing a… | |
| Aplazada | Alta (7) | 0.26% | — | Budibase ServerAI | 26/9/2026 | 28/9/2026 | Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete… | |
| Aplazada | Alta (8.7) | 0.57% | — | Budibase ServerAI | 26/9/2026 | 30/9/2026 | Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Parseplatform Parse ServerAI | 26/9/2026 | 30/9/2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber's roles are not resolved, and when a subscription does not supply its own… | |
| Pendiente de análisis | Alta (8.7) | 0.36% | — | Parseplatform Parse ServerAI | 26/9/2026 | 30/9/2026 | Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated… | |
| Aplazada | Baja (2.7) | 0.19% | — | MCP Server FOR WordpressAI | 26/9/2026 | 28/9/2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contributor role to disclose the title and publication status of any post, page or custom post type, including other users' private, draft, pending… | |
| Aplazada | Baja (2.7) | 0.17% | — | MCP Server FOR WordpressAI | 26/9/2026 | 28/9/2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the Contributor role to modify, delete and create site-wide workflow configuration, including workflows created by… | |
| Aplazada | Alta (8.8) | 0.14% | — | MCP Server FOR WordpressAI | 26/9/2026 | 28/9/2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator… | |
| Aplazada | Alta (7.1) | 0.21% | — | Actual Sync ServerAI | 25/9/2026 | 28/9/2026 | Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist. When `ACTUAL_GITHUB_TOKEN` is configured, the proxy automatically attaches the server's GitHub token to… | |
| Analizada | Media (4.5) | 0.30% | — | Broadcom Rabbitmq Server | 25/9/2026 | 6/10/2026 | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Management rendered an AMQP authorization-error reason containing an attacker-controlled queue name as HTML when the OAuth management UI was enabled. Exploitation requires an attacker with queue… | |
| Pendiente de análisis | Media (4.5) | 0.34% | — | QT VNC ServerAI | 24/9/2026 | 24/9/2026 | Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication and gain unauthorized remote access to the shared application, compromising the… | |
| Analizada | Crítica (9.1) | 0.32% | — | Claris Filemaker Server | 23/9/2026 | 5/10/2026 | An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Analizada | Crítica (9.1) | 0.29% | — | Claris Filemaker Server | 23/9/2026 | 5/10/2026 | An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Analizada | Alta (7.8) | 0.13% | — | Claris Filemaker Server | 23/9/2026 | 6/10/2026 | A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Analizada | Alta (8.6) | 0.40% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim to x264's option string on every transcode. At startup, all .so files are run without signature, execute bit, or symbol checks. | |
| Analizada | Media (5.3) | 0.22% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter. |