Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2837▲ 83 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
25.772 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.30% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack. | |
| Analizada | Crítica (9.8) | 0.97% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code. | |
| Analizada | Crítica (9.8) | 0.53% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. | |
| Analizada | Media (6.5) | 0.37% | — | IBM Websphere Application Server | 28/7/2026 | 3/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled. | |
| Analizada | Crítica (9.8) | 0.47% | — | IBM Websphere Application Server | 28/7/2026 | 3/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. | |
| Aplazada | Crítica (10) | 0.46% | — | Terraform-mcp-serverAI | 28/7/2026 | 30/7/2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in… | |
| Aplazada | Alta (8.9) | 0.36% | — | Terraform-mcp-serverAI | 28/7/2026 | 30/7/2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed… | |
| Aplazada | Alta (8.6) | 0.39% | — | Terraform-mcp-serverAI | 28/7/2026 | 30/7/2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This… | |
| Modificada | Alta (8.1) | 0.39% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling. | |
| Modificada | Alta (8.7) | 0.34% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens. | |
| Modificada | Alta (7.5) | 0.46% | — | IBM Websphere Application Server | 28/7/2026 | 23/9/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits. | |
| Analizada | Alta (7.5) | 0.77% | — | Github MCP Server | 28/7/2026 | 8/8/2026 | GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runtime panic; because… | |
| Analizada | Media (5.5) | 0.44% | — | Mattermost Server | 28/7/2026 | 29/7/2026 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint.. Mattermost Advisory ID:… | |
| Pendiente de análisis | Media (4.3) | 0.24% | — | SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI | 28/7/2026 | 28/7/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their… | |
| Aplazada | Media (5.8) | 0.40% | — | Alibabacloud RDS Openapi MCP ServerAI | 28/7/2026 | 28/7/2026 | Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default. | |
| Analizada | Media (4.3) | 0.25% | — | Devolutions Server | 27/7/2026 | 3/8/2026 | Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects : | |
| Analizada | Media (4.3) | 0.27% | — | Devolutions Server | 27/7/2026 | 3/8/2026 | Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue affects : | |
| Analizada | Alta (8.8) | 0.42% | — | Devolutions Server | 27/7/2026 | 3/8/2026 | Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects : | |
| Analizada | Media (6.5) | 0.42% | — | Mattermost Server | 27/7/2026 | 3/8/2026 | Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost… | |
| Analizada | Media (4.3) | 0.37% | — | Mattermost Server | 27/7/2026 | 3/8/2026 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly… | |
| Aplazada | Media (6.3) | 0.45% | — | Parseplatform Parse ServerAI | 24/7/2026 | 30/7/2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection: false, the default). A client holding only the public application id — with no user… | |
| Aplazada | Media (6.3) | 0.56% | — | Parseplatform Parse ServerAI | 24/7/2026 | 27/7/2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema introspection is disabled (graphQLPublicIntrospection: false, the default). Because these errors are produced… | |
| Analizada | Media (5.1) | 0.33% | — | Octopus Server | 24/7/2026 | 17/8/2026 | In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment. | |
| Aplazada | Baja (1.9) | 1.2% | — | Serverless-localstackAI | 23/7/2026 | 24/7/2026 | A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argument custom.localstack.docker.compose_file leads to os command injection. An attack has to be… | |
| Pendiente de análisis | Alta (8.7) | 0.49% | — | Johnsoncontrols VictorAIJohnsoncontrols Ccure 9000AIJohnsoncontrols Victor Application ServerAI | 23/7/2026 | 6/8/2026 | Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1. |