Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

6574 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.47%—Pyload22/4/202617/6/2026
pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after an admin changes the user's role/permissions in the database. As a result, an…
AnalizadaAlta (8.2)0.43%—Oauth2 Proxy Project Oauth2 Proxy22/4/202617/6/2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of patterns that can be…
ModificadaCrítica (9.1)0.73%—Oauth2 Proxy Project Oauth2 Proxy22/4/202615/7/2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route` is configured. An attacker can spoof this header so OAuth2 Proxy…
AnalizadaMedia (4.8)0.16%—Pyload-ng Project Pyload-ng21/4/202617/6/2026
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secure before_request handler in src/pyload/webui/app/__init__.py reads the X-Forwarded-Proto header from any HTTP request without validating that the request originates from a trusted proxy, then…
AnalizadaMedia (6.8)0.34%—Oauth2 Proxy Project Oauth2 Proxy21/4/202617/6/2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain enforcement option. An attacker may be able to authenticate with an email claim such as attacker@evil.com@company.com and satisfy an allowed…
AplazadaCrítica (9.3)0.65%—Seeyon OA A8AI21/4/202617/6/2026
Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can write JSP webshells to…
AnalizadaMedia (6.5)0.23%—Fortra Goanywhere Managed File Transfer21/4/202617/6/2026
User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclosure.
ModificadaMedia (5.4)0.15%—Fortra Goanywhere Managed File Transfer21/4/202617/6/2026
HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.
AnalizadaMedia (4.3)0.18%—Fortra Goanywhere Managed File Transfer21/4/202617/6/2026
An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.
AnalizadaMedia (4.9)0.13%—Fortra Goanywhere AgentsFortra Goanywhere Managed File Transfer21/4/20267/10/2026
Los valores cifrados en GoAnywhere MFT de Fortra, anteriores a la versión 7.10.0, y en los Agentes de GoAnywhere, anteriores a la versión 2.2.0, utilizan un IV estático que permite a los usuarios administradores forzar el descifrado de datos mediante fuerza bruta.
AnalizadaAlta (7.3)0.19%—Fortra Goanywhere Managed File Transfer21/4/20267/10/2026
El límite de intentos de inicio de sesión no se aplica en el servicio SFTP de GoAnywhere MFT de Fortra anterior a la versión 7.10.0 si el usuario web al que se intenta iniciar sesión está configurado para iniciar sesión con una clave SSH, lo que hace que la clave SSH sea vulnerable a ser adivinada mediante fuerza…
AplazadaCrítica (9.3)2.6%—NewsoftoaAI21/4/202617/6/2026
NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
AnalizadaAlta (7.2)4.2%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster20/4/202617/6/2026
OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.
AnalizadaAlta (7.2)4.2%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster20/4/202617/6/2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command
AnalizadaAlta (7.2)4.2%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster20/4/202617/6/2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command
AnalizadaAlta (7.2)4.2%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster20/4/202617/6/2026
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command
AplazadaMedia (5.5)0.66%—Rowboatlabs RowboatAI20/4/202617/6/2026
A security vulnerability has been detected in rowboatlabs rowboat up to 0.1.67. This impacts the function tool_call of the file apps/experimental/tools_webhook/app.py of the component tools_webhook. Such manipulation of the argument X-Tools-JWE leads to improper authentication. The attack may be performed from remote.…
AnalizadaMedia (5.4)0.36%—Apache-airflow-providers-keycloak18/4/202617/6/2026
The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm could deliver a crafted callback URL to a victim's browser and cause…
AnalizadaAlta (8.8)0.52%—Libcoap17/4/202617/6/2026
libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bounds checking, which is removed in release builds compiled with NDEBUG. Attackers can send crafted CoAP requests with malformed OSCORE options…
AplazadaAlta (8.1)3.5%💥 ExploitDrag AND Drop Multiple File Upload FOR Contact Form 7AI17/4/202617/6/2026
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension…
AplazadaAlta (7.5)0.59%—WP Drag AND Drop File UploadAI17/4/202617/6/2026
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without…
AplazadaAlta (8.1)0.27%—Mahmudul Hasan Arif Fluent BoardsAI15/4/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentBoards: from n/a through <= 1.91.2.
AplazadaMedia (6.4)0.33%—Coachific ShortcodeAI15/4/202617/6/2026
The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode attribute in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() on the 'userhash' parameter, which strips…
AnalizadaCrítica (9.1)0.66%—Oauth2 Proxy Project Oauth2 Proxy14/4/202624/7/2026
OAuth2 Proxy es un proxy inverso que proporciona autenticación utilizando proveedores OAuth2. Las versiones anteriores a la 7.15.2 contienen una omisión de autenticación dependiente de la configuración en implementaciones donde OAuth2 Proxy se utiliza con una integración de estilo auth_request (como nginx…
AnalizadaBaja (3.5)0.22%—Oauth2 Proxy Project Oauth2 Proxy14/4/202624/7/2026
OAuth2 Proxy es un proxy inverso que proporciona autenticación utilizando proveedores OAuth2. Una regresión introducida en 7.11.0 impide que OAuth2 Proxy borre la cookie de sesión al renderizar la página de inicio de sesión. En implementaciones que dependen de la página de inicio de sesión como parte de su flujo de…