Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

4214 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.15%—IBM Websphere Application Server29/7/20264/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
AnalizadaCrítica (9.8)0.53%—IBM Websphere Application Server29/7/20264/8/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
AplazadaMedia (6.9)0.38%—Igloohome Smart Lock Mobile APPAI28/7/202630/7/2026
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.
ModificadaAlta (8.7)0.34%—IBM Websphere Application Server28/7/20266/8/2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.
AnalizadaAlta (7.5)0.50%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.
AnalizadaAlta (7.5)0.46%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
AnalizadaCrítica (9.8)0.61%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
AnalizadaCrítica (9.8)0.68%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
AnalizadaAlta (7.5)0.45%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
AnalizadaMedia (6.1)0.30%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.
AnalizadaCrítica (9.8)0.97%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
AnalizadaCrítica (9.8)0.53%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
AnalizadaMedia (6.5)0.37%—IBM Websphere Application Server28/7/20263/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled.
AnalizadaCrítica (9.8)0.47%—IBM Websphere Application Server28/7/20263/8/2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
ModificadaAlta (8.1)0.39%—IBM Websphere Application Server28/7/202623/9/2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling.
ModificadaAlta (8.7)0.34%—IBM Websphere Application Server28/7/202623/9/2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
ModificadaAlta (7.5)0.46%—IBM Websphere Application Server28/7/202623/9/2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
AplazadaAlta (8.7)0.31%—Ghostrobotics Vision 60AIGhostrobotics Vision 60 Mobile APPAI27/7/202627/7/2026
A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can…
AplazadaMedia (6.1)0.25%—Simply Schedule AppointmentsAI27/7/202627/7/2026
Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments…
AnalizadaCrítica (9.8)0.86%—Microsoft Azure APP Service FOR Linux24/7/20266/8/2026
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (8.7)0.53%—Netapp Ontap22/7/202620/8/2026
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
Pendiente de análisisAlta (8.4)0.17%—Veeam Software ApplianceAI22/7/202623/7/2026
A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.
ModificadaMedia (5.4)0.39%—Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on17/7/202616/9/2026
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that…
ModificadaBaja (2.7)0.35%—Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on16/7/202616/9/2026
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to…
AplazadaMedia (6.1)0.38%—Webappick Product Feed Manager FOR WoocommerceAI16/7/202616/7/2026
The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…