Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
–

25.766 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.47%—Super-diamond-serverAI26/8/202631/8/2026
La interfaz de front-end /superdiamond/preview/{projectCode}/{module}/{type} de super-diamond-server <= 1.3.3 es vulnerable a inyección SQL. El parámetro module se concatena directamente en la cláusula SQL IN mediante StringUtils.split() y concatenación de cadenas sin parametrizarse ni vincularse.
AplazadaCrítica (9.8)0.61%—Super-diamond-serverAI26/8/202631/8/2026
El servicio de distribución de configuración Netty (puerto 8283) de super-diamond-server <= 1.3.3 no tiene ningún mecanismo de autenticación. Los atacantes pueden obtener directamente la configuración completa de cualquier proyecto (incluidas contraseñas de bases de datos, claves de API, etc.) enviando una solicitud…
AplazadaMedia (4.3)0.39%—Static-web-server Static WEB ServerAI26/8/20269/9/2026
Static Web Server (SWS) es un servidor web listo para producción adecuado para archivos o recursos web estáticos. Hasta la 2.43.0, las instancias con las funciones basic-auth y metrics habilitadas procesan el endpoint /metrics antes de la comprobación de basic-auth en src/handler.rs, lo que permite a un atacante…
AplazadaAlta (8.5)0.39%—Stalwart Mail ServerAI26/8/202624/9/2026
Stalwart Mail Server no compara un destino de redirección de OAuth con ningún destino registrado en su configuración predeterminada. La rutina de validación de crates/http/src/auth/oauth/registration.rs devuelve éxito inmediatamente cuando el requisito de autenticación del cliente está deshabilitado, y ese requisito…
AplazadaCrítica (9.1)1.3%—UI Unifi OS ServerAI26/8/202628/8/2026
Un actor malicioso con acceso a la red y privilegios elevados podría explotar una vulnerabilidad de validación de entrada incorrecta presente en UniFi OS Server para ejecutar una inyección de comandos en el dispositivo anfitrión.
AplazadaCrítica (9.1)0.73%—Nextcloud MCP ServerAI25/8/20269/9/2026
Nextcloud MCP Server es un servidor MCP listo para producción que conecta asistentes de IA a una instancia de Nextcloud. Antes de la 0.117.2, el endpoint POST /webhooks/nextcloud en nextcloud_mcp_server/vector/webhook_receiver.py no tiene autenticación por defecto, porque WEBHOOK_SECRET tiene como valor predeterminado…
AplazadaAlta (8.4)0.42%—Spatie Laravel Webhook ServerAI24/8/20268/9/2026
Hi.Events valida el destino de un webhook solo cuando se registra, nunca cuando se utiliza. NoInternalUrlRule en backend/app/Validators/Rules/NoInternalUrlRule.php resuelve el nombre de host con gethostbyname() y rechaza los rangos privados y reservados, algo que supera cualquier nombre de host público. En el envío,…
AplazadaMedia (6.9)0.34%—Cybertutor NewsiteserverAI24/8/202626/8/2026
NewSiteServer (NSS), desarrollado por CyberTutor, tiene una vulnerabilidad de ausencia de autenticación. Los atacantes remotos no autenticados pueden explotar una funcionalidad específica para enviar correos electrónicos a cualquier persona en nombre del centro educativo.
AplazadaMedia (5.1)0.23%—Cybertutor NewsiteserverAI24/8/202626/8/2026
NewSiteServer (NSS), desarrollado por CyberTutor, tiene una vulnerabilidad de carga arbitraria de archivos. Los atacantes remotos no autenticados pueden subir archivos arbitrarios, incluidos archivos HTML maliciosos, logrando así efectos similares a los de las secuencias de comandos en sitios cruzados (XSS).
AplazadaCrítica (9.1)0.50%—Punk Oauth2 ServerAI22/8/202626/8/2026
Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registration. token dispatches on the grant_type in…
AplazadaMedia (5.7)0.38%—Ckan MCP ServerAI21/8/20269/9/2026
CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to arbitrary endpoints without restriction. A fix was applied to filter out ip…
AplazadaBaja (3.7)0.31%—Freedom OF THE Press Foundation Securedrop ClientAIFreedom OF THE Press Foundation Securedrop ServerAIFreedom OF THE Press Foundation Securedrop-proxyAI20/8/202618/9/2026
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin limitation by responding with cross-origin redirects. SecureDrop Server itself has…
AplazadaAlta (8.7)0.54%—FDS WEB ServerAI20/8/20263/9/2026
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be…
AnalizadaAlta (7.1)0.23%—Octopus Server20/8/20262/9/2026
In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text.
AnalizadaCrítica (9.1)0.75%—Splunk Model Context Protocol Server19/8/202624/8/2026
In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking…
AnalizadaAlta (7)0.20%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+919/8/20268/9/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.5)1.7%⚠ Explotación activa💥 PoCTrueconf Server19/8/202621/8/2026
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
AnalizadaCrítica (9.3)1.5%⚠ Explotación activaTrueconf Server19/8/202621/8/2026
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Pendiente de análisisMedia (6.8)0.15%—RenovateAIMend Renovate-ceAIRenovate-ee-serverAIRenovate-ee-workerAI19/8/20268/10/2026
Renovate versions from 42.68.1 before 42.96.3 and from 43.0.0 before 43.4.4, including the renovate/renovate Docker images, and Mend Renovate CE/EE images (renovate-ce, renovate-ee-server, renovate-ee-worker) from 13.3.0 before 13.6.0, fail to restrict environment variables to an allowlist when spawning child…
Pendiente de análisisCrítica (9.3)0.51%—Atlassian Confluence Data CenterAIAtlassian Confluence ServerAI18/8/202626/8/2026
This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS,…
AnalizadaCrítica (9.1)0.45%—Oracle Database Server18/8/202620/8/2026
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Portable Clusterware. Successful attacks of this…
AnalizadaMedia (5.3)0.32%—Oracle Database Server18/8/202620/8/2026
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can…
ModificadaCrítica (9.6)0.40%—Oracle Database Server18/8/202622/8/2026
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the…
AnalizadaCrítica (9.6)0.40%—Oracle Database Server18/8/202620/8/2026
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the…
AnalizadaAlta (8.5)0.33%—Oracle Database Server18/8/202620/8/2026
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS,…