Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2886▲ 263 respecto a la semana anterior
Críticas / altas1344▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

25.937 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.9)0.57%—Progress Marklogic Server5/8/20263/9/2026
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized…
AnalizadaAlta (8.1)0.39%—Progress Marklogic Server5/8/20263/9/2026
An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is…
AnalizadaAlta (8.8)0.21%—Progress Marklogic Server5/8/20263/9/2026
A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security…
AplazadaMedia (6.9)0.41%—M-files ServerAI5/8/202631/8/2026
Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart.
AplazadaCrítica (9.8)0.48%—Aerie Plandev Sequencing ServerAIHasuraAI5/8/202626/8/2026
The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no…
AnalizadaAlta (7.1)0.23%—Nvidia Triton Inference Server4/8/202617/8/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of service and information…
AplazadaCrítica (9.8)1.9%—Serverless-devs SAI3/8/20269/9/2026
The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in ".git" bypasses the only input check, allowing OS command injection when a user runs "s init" with an attacker-controlled argument.
Pendiente de análisisAlta (7.1)0.42%—Awslabs Amazon MQ MCP ServerAIAmazon MQAI3/8/20264/8/2026
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted…
AnalizadaMedia (5.4)0.28%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux3/8/20269/8/2026
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on…
Pendiente de análisisCrítica (9.3)0.89%💥 PoCCheckpoint Security Management ServerAICheckpoint Multi Domain Security Management ServerAI3/8/20265/8/2026
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could…
AplazadaCrítica (10)0.71%—Wapt ServerAI3/8/20261/9/2026
A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.
AplazadaCrítica (9.8)1.1%—Hiawatha-webserver HiawathaAI31/7/202631/8/2026
An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request
ModificadaAlta (7.5)0.83%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux31/7/20268/10/2026
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by…
ModificadaAlta (7.5)0.53%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux31/7/20268/10/2026
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the…
AplazadaMedia (6.9)0.29%—ABB MMS ServerAI30/7/20268/9/2026
The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing bounds check. This results in a one byte…
AplazadaMedia (6.1)0.34%—Adonisjs Http ServerAI30/7/202610/9/2026
AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the error.message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route URL to execute attacker-controlled…
AnalizadaAlta (8.5)0.58%—IBM Websphere Application Server30/7/20265/8/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
AnalizadaAlta (7.5)0.56%—IBM Websphere Application Server30/7/202612/8/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
AnalizadaAlta (7.5)0.53%—IBM Websphere Application Server30/7/20265/8/2026
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.
AnalizadaAlta (8.8)0.43%—IBM Websphere Application Server30/7/20264/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.
AnalizadaAlta (7.5)0.53%—IBM Websphere Application Server30/7/20264/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
AnalizadaCrítica (9.3)0.38%—IBM Websphere Application ServerIBM Tivoli System Automation Application Manager30/7/202618/8/2026
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
AnalizadaMedia (5.4)0.23%—IBM Websphere Application ServerIBM Tivoli System Automation Application Manager30/7/202618/8/2026
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console.
AnalizadaCrítica (9.8)2.6%⚠ Explotación activa💥 PoCVmware Vcenter Server30/7/202619/8/2026
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
AnalizadaCrítica (9.8)0.61%—Vmware Vcenter Server30/7/202625/8/2026
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.