Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2716▼ 25 respecto a la semana anterior
Críticas / altas1269▼ 244 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
25.772 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.35% | — | Wso2 Identity Server | 6/8/2026 | 29/9/2026 | El sistema acepta solicitudes de autenticación sin validación suficiente para hacer cumplir el aislamiento de inquilinos al usar OTP por correo electrónico, OTP por SMS o Magic Link como autenticadores de primer factor. Esta falla al separar adecuadamente los datos de usuario entre inquilinos puede llevar a la… | |
| Analizada | Baja (3.7) | 0.27% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+1 | 6/8/2026 | 29/9/2026 | Cuando el inicio de sesión multiatributo está habilitado, la interfaz de inicio de sesión no logra enmascarar consistentemente la existencia de cuentas de usuario. Para usuarios válidos, el servidor resuelve y muestra su nombre de usuario canónico, mientras que para usuarios inexistentes, se hace eco de la entrada… | |
| Analizada | Media (5.4) | 0.14% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 6/8/2026 | 29/9/2026 | El procesador Ajax dentro de la consola Carbon no protege adecuadamente las operaciones que cambian el estado de ataques de falsificación de petición en sitios cruzados (CSRF). Específicamente, utiliza el método HTTP GET para estas operaciones, y aunque el atributo de cookie SameSite=Lax se emplea para la mitigación,… | |
| Analizada | Baja (2.4) | 0.20% | — | Wso2 Identity Server | 6/8/2026 | 29/9/2026 | El flujo de suplantación de identidad de usuario en WSO2 Identity Server no gestiona adecuadamente los tokens de actualización asociados con sesiones suplantadas. Esto permite a un atacante que ha obtenido un token de acceso para un usuario suplantado aprovechar la concesión de token de actualización para obtener… | |
| Analizada | Media (4.3) | 0.31% | — | Wso2 Identity Server | 6/8/2026 | 29/9/2026 | Cuando se configuran almacenes de usuarios secundarios, el resolutor de asociación implícita se inicializa incorrectamente desde un almacén de usuarios secundario y omite el almacén de usuarios principal durante las comprobaciones de búsqueda y unicidad. Esto permite que un sujeto se asocie con una cuenta local no… | |
| Analizada | Media (6.6) | 0.77% | — | Github Enterprise Server | 5/8/2026 | 18/8/2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of request-handling worker processes by sending a crafted form-encoded HTTP POST request containing deeply nested parameters. Because request… | |
| Aplazada | Media (5.3) | 0.33% | — | Spacebar ServerAI | 5/8/2026 | 16/9/2026 | Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids endpoint without guild membership verification. Attackers can exploit the unprotected route… | |
| Aplazada | Alta (8.6) | 0.41% | — | Spacebar ServerAI | 5/8/2026 | 16/9/2026 | Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT… | |
| Analizada | Media (5.7) | 0.16% | — | Amazon Documentdb MCP Server | 5/8/2026 | 10/8/2026 | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To… | |
| Analizada | Media (6.3) | 0.18% | 💥 PoC | Amazon AWS Transform MCP Server | 5/8/2026 | 10/8/2026 | Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. To remediate this issue, users should… | |
| Analizada | Alta (8.8) | 0.80% | — | Github Enterprise Server | 5/8/2026 | 18/8/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and avatars. The X-GitHub-Request-Id request… | |
| Analizada | Alta (8.5) | 0.34% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the… | |
| Analizada | Crítica (9.3) | 0.65% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions… | |
| Analizada | Crítica (9.9) | 0.46% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database. | |
| Analizada | Crítica (9.8) | 0.83% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators. | |
| Analizada | Crítica (9.1) | 0.74% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing… | |
| Analizada | Crítica (9.9) | 0.46% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database. | |
| Analizada | Crítica (9.8) | 0.48% | — | IBM Websphere Application Server | 5/8/2026 | 10/8/2026 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. | |
| Analizada | Crítica (9.1) | 0.46% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with… | |
| Analizada | Crítica (9.9) | 0.57% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized… | |
| Analizada | Alta (8.1) | 0.39% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is… | |
| Analizada | Alta (8.8) | 0.21% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security… | |
| Aplazada | Media (6.9) | 0.41% | — | M-files ServerAI | 5/8/2026 | 31/8/2026 | Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Aerie Plandev Sequencing ServerAIHasuraAI | 5/8/2026 | 26/8/2026 | The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no… | |
| Analizada | Alta (7.1) | 0.23% | — | Nvidia Triton Inference Server | 4/8/2026 | 17/8/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of service and information… |