Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
25.937 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.14% | — | Feedmob Fm-mcp-serversAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery. The attack can only be… | |
| Analizada | Media (6.5) | 0.39% | — | Elastic Fleet Server | 13/8/2026 | 4/9/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-supplied value that was persisted without being validated against the server-side… | |
| Analizada | Crítica (9.4) | 0.55% | — | IBM Websphere Application Server | 13/8/2026 | 17/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. | |
| Analizada | Media (5.3) | 0.59% | — | IBM Websphere Application Server | 13/8/2026 | 17/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled. | |
| Pendiente de análisis | Media (5.3) | 0.53% | — | Hono Node-serverAI | 13/8/2026 | 10/9/2026 | @hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header causes src/websocket.ts to retain the request's IncomingMessage in waiterMap and leave waitForWebSocket pending… | |
| Aplazada | Alta (8.7) | 0.36% | — | Budibase ServerAI | 13/8/2026 | 8/10/2026 | Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to… | |
| Modificada | Media (6.5) | 0.42% | — | Mattermost Server | 13/8/2026 | 14/9/2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an authenticated user to cause memory exhaustion or unbounded disk consumption via a… | |
| Aplazada | Alta (7.5) | 1.4% | 💥 Exploit | Fuxa-serverAI | 12/8/2026 | 16/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue. | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Http4s-blaze-serverAI | 12/8/2026 | 10/9/2026 | Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated… | |
| Analizada | Alta (7.3) | 0.43% | — | IBM Informix Dynamic Server | 12/8/2026 | 18/8/2026 | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input. | |
| Analizada | Alta (7.8) | 0.14% | — | IBM Informix Dynamic Server | 12/8/2026 | 18/8/2026 | IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility. | |
| Analizada | Alta (8.8) | 0.49% | — | IBM Informix Dynamic Server | 12/8/2026 | 18/8/2026 | IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field. | |
| Analizada | Alta (8.1) | 0.42% | — | IBM Websphere Application Server | 12/8/2026 | 17/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives. | |
| Aplazada | Baja (2.3) | 0.37% | — | Temporal UI ServerAI | 11/8/2026 | 8/9/2026 | When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure attributes from the proxy-to-server connection. Temporal UI Server can therefore issue access-token cookies, and… | |
| Modificada | Alta (8.1) | 0.71% | — | Microsoft Windows 10 1809Microsoft Windows Server 2019Microsoft Windows Server 2022Microsoft Windows Server 2025 | 11/8/2026 | 20/8/2026 | Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.7) | 0.78% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Desbordamiento de búfer basado en montón (heap) en Windows Installer permite a un atacante autorizado elevar privilegios localmente. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Desbordamiento de búfer basado en montón (heap) en Windows Installer permite a un atacante autorizado elevar privilegios localmente. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.34% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 18/8/2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 1.7% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |