Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▼ 12 respecto a la semana anterior
Críticas / altas1272▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

25.772 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)1.9%—Serverless-devs SAI3/8/20269/9/2026
The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in ".git" bypasses the only input check, allowing OS command injection when a user runs "s init" with an attacker-controlled argument.
Pendiente de análisisAlta (7.1)0.42%—Awslabs Amazon MQ MCP ServerAIAmazon MQAI3/8/20264/8/2026
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted…
AnalizadaMedia (5.4)0.28%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux3/8/20269/8/2026
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on…
Pendiente de análisisCrítica (9.3)0.89%💥 PoCCheckpoint Security Management ServerAICheckpoint Multi Domain Security Management ServerAI3/8/20265/8/2026
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could…
AplazadaCrítica (10)0.71%—Wapt ServerAI3/8/20261/9/2026
A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.
AplazadaCrítica (9.8)1.1%—Hiawatha-webserver HiawathaAI31/7/202631/8/2026
An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request
ModificadaAlta (7.5)0.83%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux31/7/20268/10/2026
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by…
ModificadaAlta (7.5)0.53%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux31/7/20268/10/2026
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the…
AplazadaMedia (6.9)0.29%—ABB MMS ServerAI30/7/20268/9/2026
The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing bounds check. This results in a one byte…
AplazadaMedia (6.1)0.34%—Adonisjs Http ServerAI30/7/202610/9/2026
AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the error.message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route URL to execute attacker-controlled…
AnalizadaAlta (8.5)0.58%—IBM Websphere Application Server30/7/20265/8/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
AnalizadaAlta (7.5)0.56%—IBM Websphere Application Server30/7/202612/8/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
AnalizadaAlta (7.5)0.53%—IBM Websphere Application Server30/7/20265/8/2026
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.
AnalizadaAlta (8.8)0.43%—IBM Websphere Application Server30/7/20264/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.
AnalizadaAlta (7.5)0.53%—IBM Websphere Application Server30/7/20264/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
AnalizadaCrítica (9.3)0.38%—IBM Websphere Application ServerIBM Tivoli System Automation Application Manager30/7/202618/8/2026
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
AnalizadaMedia (5.4)0.23%—IBM Websphere Application ServerIBM Tivoli System Automation Application Manager30/7/202618/8/2026
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console.
AnalizadaCrítica (9.8)2.6%⚠ Explotación activa💥 PoCVmware Vcenter Server30/7/202619/8/2026
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
AnalizadaCrítica (9.8)0.61%—Vmware Vcenter Server30/7/202625/8/2026
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
AplazadaAlta (8.7)0.56%—Charx Modbus ServerAI30/7/202630/7/2026
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
AplazadaAlta (8.8)0.68%—Mobus ServerAI30/7/202630/7/2026
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
AnalizadaAlta (8.8)0.15%—IBM Websphere Application Server29/7/20264/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
AplazadaAlta (8.6)0.39%—Consul-mcp-serverAI29/7/202630/7/2026
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled…
AplazadaCrítica (10)0.54%—Hashicorp Consul-mcp-serverAI29/7/202630/7/2026
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
AnalizadaCrítica (9.8)0.53%—IBM Websphere Application Server29/7/20264/8/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.