Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2837▲ 83 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

25.772 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.30%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.
AnalizadaCrítica (9.8)0.97%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
AnalizadaCrítica (9.8)0.53%—IBM Websphere Application Server28/7/20265/8/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
AnalizadaMedia (6.5)0.37%—IBM Websphere Application Server28/7/20263/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled.
AnalizadaCrítica (9.8)0.47%—IBM Websphere Application Server28/7/20263/8/2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
AplazadaCrítica (10)0.46%—Terraform-mcp-serverAI28/7/202630/7/2026
The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in…
AplazadaAlta (8.9)0.36%—Terraform-mcp-serverAI28/7/202630/7/2026
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed…
AplazadaAlta (8.6)0.39%—Terraform-mcp-serverAI28/7/202630/7/2026
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This…
ModificadaAlta (8.1)0.39%—IBM Websphere Application Server28/7/202623/9/2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling.
ModificadaAlta (8.7)0.34%—IBM Websphere Application Server28/7/202623/9/2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
ModificadaAlta (7.5)0.46%—IBM Websphere Application Server28/7/202623/9/2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
AnalizadaAlta (7.5)0.77%—Github MCP Server28/7/20268/8/2026
GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runtime panic; because…
AnalizadaMedia (5.5)0.44%—Mattermost Server28/7/202629/7/2026
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint.. Mattermost Advisory ID:…
Pendiente de análisisMedia (4.3)0.24%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI28/7/202628/7/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their…
AplazadaMedia (5.8)0.40%—Alibabacloud RDS Openapi MCP ServerAI28/7/202628/7/2026
Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.
AnalizadaMedia (4.3)0.25%—Devolutions Server27/7/20263/8/2026
Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects :
AnalizadaMedia (4.3)0.27%—Devolutions Server27/7/20263/8/2026
Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue affects :
AnalizadaAlta (8.8)0.42%—Devolutions Server27/7/20263/8/2026
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects :
AnalizadaMedia (6.5)0.42%—Mattermost Server27/7/20263/8/2026
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost…
AnalizadaMedia (4.3)0.37%—Mattermost Server27/7/20263/8/2026
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly…
AplazadaMedia (6.3)0.45%—Parseplatform Parse ServerAI24/7/202630/7/2026
Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection: false, the default). A client holding only the public application id — with no user…
AplazadaMedia (6.3)0.56%—Parseplatform Parse ServerAI24/7/202627/7/2026
Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema introspection is disabled (graphQLPublicIntrospection: false, the default). Because these errors are produced…
AnalizadaMedia (5.1)0.33%—Octopus Server24/7/202617/8/2026
In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.
AplazadaBaja (1.9)1.2%—Serverless-localstackAI23/7/202624/7/2026
A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argument custom.localstack.docker.compose_file leads to os command injection. An attack has to be…
Pendiente de análisisAlta (8.7)0.49%—Johnsoncontrols VictorAIJohnsoncontrols Ccure 9000AIJohnsoncontrols Victor Application ServerAI23/7/20266/8/2026
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.