Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2886▲ 263 respecto a la semana anterior
Críticas / altas1344▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
25.937 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.9) | 0.57% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized… | |
| Analizada | Alta (8.1) | 0.39% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is… | |
| Analizada | Alta (8.8) | 0.21% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security… | |
| Aplazada | Media (6.9) | 0.41% | — | M-files ServerAI | 5/8/2026 | 31/8/2026 | Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Aerie Plandev Sequencing ServerAIHasuraAI | 5/8/2026 | 26/8/2026 | The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no… | |
| Analizada | Alta (7.1) | 0.23% | — | Nvidia Triton Inference Server | 4/8/2026 | 17/8/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of service and information… | |
| Aplazada | Crítica (9.8) | 1.9% | — | Serverless-devs SAI | 3/8/2026 | 9/9/2026 | The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in ".git" bypasses the only input check, allowing OS command injection when a user runs "s init" with an attacker-controlled argument. | |
| Pendiente de análisis | Alta (7.1) | 0.42% | — | Awslabs Amazon MQ MCP ServerAIAmazon MQAI | 3/8/2026 | 4/8/2026 | Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted… | |
| Analizada | Media (5.4) | 0.28% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 3/8/2026 | 9/8/2026 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on… | |
| Pendiente de análisis | Crítica (9.3) | 0.89% | 💥 PoC | Checkpoint Security Management ServerAICheckpoint Multi Domain Security Management ServerAI | 3/8/2026 | 5/8/2026 | An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could… | |
| Aplazada | Crítica (10) | 0.71% | — | Wapt ServerAI | 3/8/2026 | 1/9/2026 | A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Hiawatha-webserver HiawathaAI | 31/7/2026 | 31/8/2026 | An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request | |
| Modificada | Alta (7.5) | 0.83% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 31/7/2026 | 8/10/2026 | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by… | |
| Modificada | Alta (7.5) | 0.53% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 31/7/2026 | 8/10/2026 | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the… | |
| Aplazada | Media (6.9) | 0.29% | — | ABB MMS ServerAI | 30/7/2026 | 8/9/2026 | The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing bounds check. This results in a one byte… | |
| Aplazada | Media (6.1) | 0.34% | — | Adonisjs Http ServerAI | 30/7/2026 | 10/9/2026 | AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the error.message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route URL to execute attacker-controlled… | |
| Analizada | Alta (8.5) | 0.58% | — | IBM Websphere Application Server | 30/7/2026 | 5/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector. | |
| Analizada | Alta (7.5) | 0.56% | — | IBM Websphere Application Server | 30/7/2026 | 12/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request. | |
| Analizada | Alta (7.5) | 0.53% | — | IBM Websphere Application Server | 30/7/2026 | 5/8/2026 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints. | |
| Analizada | Alta (8.8) | 0.43% | — | IBM Websphere Application Server | 30/7/2026 | 4/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled. | |
| Analizada | Alta (7.5) | 0.53% | — | IBM Websphere Application Server | 30/7/2026 | 4/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console. | |
| Analizada | Crítica (9.8) | 2.6% | ⚠ Explotación activa💥 PoC | Vmware Vcenter Server | 30/7/2026 | 19/8/2026 | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. | |
| Analizada | Crítica (9.8) | 0.61% | — | Vmware Vcenter Server | 30/7/2026 | 25/8/2026 | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system. |