Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

25.937 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.4)0.16%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+46/8/202612/8/2026
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such…
AnalizadaMedia (4.9)0.19%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+46/8/202613/8/2026
Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client…
AnalizadaAlta (7.5)0.41%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+46/8/20269/8/2026
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the…
En análisisMedia (5.8)0.29%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+36/8/20269/8/2026
The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidated input into user claims can lead to various security risks. Malicious…
AnalizadaCrítica (9.4)0.67%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+56/8/202629/9/2026
El script de autenticación condicional (autenticación adaptativa) no aplica correctamente la finalización de todos los pasos de autenticación requeridos cuando se configura un patrón específico de múltiples pasos que involucra ciertos autenticadores. Esto permite a un atacante eludir los desafíos de autenticación…
AnalizadaBaja (3.8)0.32%—Wso2 Identity Server6/8/202629/9/2026
La API REST de Gestión de Tipos de Secreto no aísla correctamente los controles de acceso al eliminar un tipo de secreto. La lógica de cascada al eliminar, cuando se activa, no logra aplicar los límites organizacionales, lo que lleva a la eliminación de secretos asociados con ese tipo en todas las organizaciones. La…
AnalizadaMedia (4.3)0.35%—Wso2 Identity Server6/8/202629/9/2026
El sistema acepta solicitudes de autenticación sin validación suficiente para hacer cumplir el aislamiento de inquilinos al usar OTP por correo electrónico, OTP por SMS o Magic Link como autenticadores de primer factor. Esta falla al separar adecuadamente los datos de usuario entre inquilinos puede llevar a la…
AnalizadaBaja (3.7)0.27%—Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+16/8/202629/9/2026
Cuando el inicio de sesión multiatributo está habilitado, la interfaz de inicio de sesión no logra enmascarar consistentemente la existencia de cuentas de usuario. Para usuarios válidos, el servidor resuelve y muestra su nombre de usuario canónico, mientras que para usuarios inexistentes, se hace eco de la entrada…
AnalizadaMedia (5.4)0.14%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+56/8/202629/9/2026
El procesador Ajax dentro de la consola Carbon no protege adecuadamente las operaciones que cambian el estado de ataques de falsificación de petición en sitios cruzados (CSRF). Específicamente, utiliza el método HTTP GET para estas operaciones, y aunque el atributo de cookie SameSite=Lax se emplea para la mitigación,…
AnalizadaBaja (2.4)0.20%—Wso2 Identity Server6/8/202629/9/2026
El flujo de suplantación de identidad de usuario en WSO2 Identity Server no gestiona adecuadamente los tokens de actualización asociados con sesiones suplantadas. Esto permite a un atacante que ha obtenido un token de acceso para un usuario suplantado aprovechar la concesión de token de actualización para obtener…
AnalizadaMedia (4.3)0.31%—Wso2 Identity Server6/8/202629/9/2026
Cuando se configuran almacenes de usuarios secundarios, el resolutor de asociación implícita se inicializa incorrectamente desde un almacén de usuarios secundario y omite el almacén de usuarios principal durante las comprobaciones de búsqueda y unicidad. Esto permite que un sujeto se asocie con una cuenta local no…
AnalizadaMedia (6.6)0.77%—Github Enterprise Server5/8/202618/8/2026
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of request-handling worker processes by sending a crafted form-encoded HTTP POST request containing deeply nested parameters. Because request…
AplazadaMedia (5.3)0.33%—Spacebar ServerAI5/8/202616/9/2026
Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids endpoint without guild membership verification. Attackers can exploit the unprotected route…
AplazadaAlta (8.6)0.41%—Spacebar ServerAI5/8/202616/9/2026
Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT…
AnalizadaMedia (5.7)0.16%—Amazon Documentdb MCP Server5/8/202610/8/2026
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To…
AnalizadaMedia (6.3)0.18%💥 PoCAmazon AWS Transform MCP Server5/8/202610/8/2026
Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. To remediate this issue, users should…
AnalizadaAlta (8.8)0.80%—Github Enterprise Server5/8/202618/8/2026
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and avatars. The X-GitHub-Request-Id request…
AnalizadaAlta (8.5)0.34%—Progress Marklogic Server5/8/20263/9/2026
A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the…
AnalizadaCrítica (9.3)0.65%—Progress Marklogic Server5/8/20263/9/2026
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions…
AnalizadaCrítica (9.9)0.46%—Progress Marklogic Server5/8/20263/9/2026
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
AnalizadaCrítica (9.8)0.83%—Progress Marklogic Server5/8/20263/9/2026
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
AnalizadaCrítica (9.1)0.74%—Progress Marklogic Server5/8/20263/9/2026
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing…
AnalizadaCrítica (9.9)0.46%—Progress Marklogic Server5/8/20263/9/2026
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.
AnalizadaCrítica (9.8)0.48%—IBM Websphere Application Server5/8/202610/8/2026
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
AnalizadaCrítica (9.1)0.46%—Progress Marklogic Server5/8/20263/9/2026
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with…