Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
25.870 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.23% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters. | |
| Analizada | Media (5.3) | 0.22% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination. | |
| Analizada | Alta (7.1) | 0.52% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken,… | |
| Aplazada | Crítica (9) | 0.19% | — | WP Oauth ServerAI | 23/9/2026 | 24/9/2026 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and… | |
| Analizada | Crítica (9.3) | 0.68% | — | Github Enterprise Server | 22/9/2026 | 2/10/2026 | A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same… | |
| Analizada | Alta (7.4) | 0.21% | — | Github Enterprise Server | 22/9/2026 | 2/10/2026 | A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrote quote characters in already-sanitized HTML without re-sanitizing the result.… | |
| Analizada | Media (6) | 0.29% | — | Github Enterprise Server | 22/9/2026 | 2/10/2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tokens for raw pull request diffs and patches were scoped to the repository name and… | |
| Aplazada | Crítica (9.1) | 0.27% | — | Apache Http ServerAI | 22/9/2026 | 23/9/2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users. | |
| Aplazada | Alta (8.4) | 0.13% | — | Apache Http ServerAIOpensslAI | 22/9/2026 | 23/9/2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution. | |
| Aplazada | Media (4.3) | 0.23% | — | Joplin ServerAI | 21/9/2026 | 24/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to items with a share ID when any share_users row exists for the caller, without requiring ShareUserStatus.Accepted. A low-privileged… | |
| Aplazada | Alta (7.6) | 0.35% | — | Joplin ServerAI | 21/9/2026 | 23/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's GET /shares/:id?resource_id= route serves a resource with the attacker-controlled mime value and omits Content-Disposition when the resource title is empty. A low-privileged user… | |
| Aplazada | Alta (7.4) | 0.48% | — | Joplin ServerAI | 21/9/2026 | 23/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's UserModel.ssoLogin() returns an existing account matched by an IdP-asserted email without checking the account's is_external flag. In deployments using mixed local and SAML… | |
| Aplazada | Media (4.3) | 0.36% | — | Joplin ServerAI | 21/9/2026 | 23/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, the GET /api/transcribe/:id and POST /api/transcribe/:id handlers in packages/server/src/routes/api/transcribe.ts on Joplin Server instances with TRANSCRIBE_ENABLED=true pass the decoded id… | |
| Aplazada | Media (5.3) | 0.34% | — | Sync-in ServerAI | 21/9/2026 | 30/9/2026 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login endpoint because authentication attempts for nonexistent accounts return without performing the bcrypt comparison used for existing accounts. An… | |
| Aplazada | Media (6.5) | 0.35% | — | Sync-in ServerAI | 21/9/2026 | 24/9/2026 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no complexity validation. A catastrophic-backtracking pattern (e.g. `^(a+)+b`) blocks the Node.js event loop, making the… | |
| Aplazada | Media (6.5) | 0.26% | — | Joplin ServerAI | 21/9/2026 | 23/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in packages/server/src/routes/index/items.ts loads item content from an attacker-supplied internal server ID without checking whether the signed-in user… | |
| Aplazada | Crítica (9.1) | 0.50% | — | Joplin ServerAI | 21/9/2026 | 28/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker… | |
| Aplazada | Alta (8.1) | 0.22% | — | Sync-in ServerAI | 21/9/2026 | 24/9/2026 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full access and refresh JWTs without checking whether the account has TOTP 2FA enabled.… | |
| Aplazada | Media (5.7) | 0.23% | — | Ondata Ckan MCP ServerAI | 21/9/2026 | 24/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the hostname string and never resolves DNS. Any caller-supplied `server_url` whose hostname *resolves* to an internal… | |
| Aplazada | Baja (2.1) | 0.45% | — | ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI | 21/9/2026 | 30/9/2026 | A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /authorize of the component HTTP Request Handler. Executing a manipulation of the argument Success can lead to http response splitting. It is possible to launch the… | |
| Aplazada | Baja (2.1) | 0.46% | — | ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI | 21/9/2026 | 30/9/2026 | A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has… | |
| Pendiente de análisis | Alta (8.7) | 0.58% | — | Temporal-serverAI | 21/9/2026 | 22/9/2026 | Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Worker Service. The program name and the argument vector that provider executes are… | |
| Pendiente de análisis | Alta (7.2) | 0.78% | — | Temporal ServerAI | 21/9/2026 | 22/9/2026 | Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a single namespace could attach a completion callback whose URL host matched the configured callback address allowlist, whose URL path was any… | |
| Pendiente de análisis | Media (4.8) | 0.18% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. | |
| Pendiente de análisis | Media (6.5) | 0.38% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component. |