Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

25.872 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.23%—IBM Websphere Application ServerAI18/9/202622/9/2026
IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.
Pendiente de análisisMedia (6.5)0.23%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202622/9/2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.
Pendiente de análisisMedia (4.8)0.18%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202622/9/2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
Pendiente de análisisBaja (3.7)0.26%—IBM Websphere Application ServerAI18/9/202622/9/2026
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.
Pendiente de análisisMedia (5.3)0.30%—IBM Websphere Application ServerAI18/9/202622/9/2026
IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
Pendiente de análisisMedia (5.3)0.30%—IBM Websphere Application ServerAI18/9/202622/9/2026
IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.
AnalizadaMedia (5.3)0.16%—IBM Websphere Application Server18/9/202624/9/2026
IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.
Pendiente de análisisMedia (4.3)0.18%—IBM Websphere Application ServerAI18/9/202619/9/2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
En análisisMedia (4.8)0.18%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202630/9/2026
IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
Pendiente de análisisCrítica (10)0.62%—Prebid Server JavaAI17/9/202623/9/2026
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request parameters can cause the server to send…
Pendiente de análisisAlta (7.1)0.42%—Jupyter ServerAI17/9/202624/9/2026
Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for the request URI. A request that returns HTTP 500 while the Referer contains a…
Pendiente de análisisMedia (5.3)0.50%—MapserverAI17/9/202630/9/2026
MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTP_X_FORWARDED_HOST through msBuildOnlineResource(), processLine(),…
Pendiente de análisisAlta (8.2)0.68%—MapserverAIPostgisAI17/9/202624/9/2026
MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml_<item>_type=Integer are configured, but it does…
AplazadaAlta (8.7)0.52%—EspasynchttpserverAI17/9/202624/9/2026
ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPosition as an 8-bit value while _parseMultipartPostByte processes the boundary. A remote request containing an exactly…
AplazadaAlta (8.8)0.57%—MCP Documentation ServerAI17/9/202630/9/2026
MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with START_WEB_UI enabled by default and WEB_PORT set to 3080. startWebServer uses…
AplazadaAlta (8.1)0.62%—Labs64 Netlicensing MCP ServerAI17/9/202630/9/2026
NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-netlicensing-api-key, Authorization: Bearer, and the apikey query parameter pass…
Pendiente de análisisAlta (8.2)0.19%—Dell Server Update UtilityAI17/9/202619/9/2026
Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
AplazadaAlta (8.7)0.66%—Internlm LmdeployAIDistserveAI17/9/202622/9/2026
InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys. Unauthenticated attackers can send completion requests to the proxy endpoint that accumulate unreleased scheduler…
AnalizadaMedia (6.8)0.13%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
AnalizadaAlta (7.4)0.37%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
AnalizadaAlta (7.2)0.46%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaAlta (7.3)0.14%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
AnalizadaMedia (6.5)0.45%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
AnalizadaMedia (6.4)0.23%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
AnalizadaAlta (8.1)0.38%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access.