Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3077▲ 447 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
25.937 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.7) | 0.34% | — | IBM Websphere Application Server | 28/7/2026 | 6/8/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests. | |
| Analizada | Alta (7.5) | 0.50% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation. | |
| Analizada | Crítica (9.8) | 0.61% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled. | |
| Analizada | Crítica (9.8) | 0.68% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data. | |
| Analizada | Alta (7.5) | 0.45% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information. | |
| Analizada | Media (6.1) | 0.30% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack. | |
| Analizada | Crítica (9.8) | 0.97% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code. | |
| Analizada | Crítica (9.8) | 0.53% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. | |
| Analizada | Media (6.5) | 0.37% | — | IBM Websphere Application Server | 28/7/2026 | 3/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled. | |
| Analizada | Crítica (9.8) | 0.47% | — | IBM Websphere Application Server | 28/7/2026 | 3/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. | |
| Aplazada | Crítica (10) | 0.46% | — | Terraform-mcp-serverAI | 28/7/2026 | 30/7/2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in… | |
| Aplazada | Alta (8.9) | 0.36% | — | Terraform-mcp-serverAI | 28/7/2026 | 30/7/2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed… | |
| Aplazada | Alta (8.6) | 0.39% | — | Terraform-mcp-serverAI | 28/7/2026 | 30/7/2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This… | |
| Modificada | Alta (8.1) | 0.39% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling. | |
| Modificada | Alta (8.7) | 0.34% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens. | |
| Modificada | Alta (7.5) | 0.46% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits. | |
| Analizada | Alta (7.5) | 0.77% | — | Github MCP Server | 28/7/2026 | 8/8/2026 | GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runtime panic; because… | |
| Analizada | Media (5.5) | 0.44% | — | Mattermost Server | 28/7/2026 | 29/7/2026 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint.. Mattermost Advisory ID:… | |
| Pendiente de análisis | Media (4.3) | 0.24% | — | SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI | 28/7/2026 | 28/7/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their… | |
| Aplazada | Media (5.8) | 0.40% | — | Alibabacloud RDS Openapi MCP ServerAI | 28/7/2026 | 28/7/2026 | Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default. | |
| Analizada | Media (4.3) | 0.25% | — | Devolutions Server | 27/7/2026 | 3/8/2026 | Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects : | |
| Analizada | Media (4.3) | 0.27% | — | Devolutions Server | 27/7/2026 | 3/8/2026 | Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue affects : | |
| Analizada | Alta (8.8) | 0.42% | — | Devolutions Server | 27/7/2026 | 3/8/2026 | Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects : | |
| Analizada | Media (6.5) | 0.42% | — | Mattermost Server | 27/7/2026 | 3/8/2026 | Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost… |