Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
25.937 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.14% | — | Revive AdserverAI | 20/7/2026 | 23/7/2026 | A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated… | |
| Analizada | Alta (7.1) | 0.21% | — | Verygoodplugins Whatsapp MCP Server | 20/7/2026 | 18/8/2026 | WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint accepts an absolute… | |
| Analizada | Media (6.1) | 0.25% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity Server | 20/7/2026 | 19/8/2026 | The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacker can leverage this vulnerability to cause the user's browser to… | |
| Pendiente de análisis | Crítica (9.4) | 0.92% | — | Konnectivity Proxy ServerAI | 20/7/2026 | 14/9/2026 | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could… | |
| Analizada | Alta (7.5) | 0.74% | — | Apache Traffic Server | 18/7/2026 | 6/8/2026 | Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue. | |
| Pendiente de análisis | Media (6.8) | 0.35% | — | Amazon Healthomics MCP ServerAI | 17/7/2026 | 20/7/2026 | AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. Improper limitation of a pathname to a restricted directory in the linting tools… | |
| Aplazada | Alta (8.7) | 0.52% | — | Open Event ServerAI | 17/7/2026 | 17/7/2026 | Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submitting requests to the group followers CSV export endpoint which lacks any… | |
| Aplazada | Media (5.3) | 0.45% | — | Github Enterprise ServerAI | 17/7/2026 | 17/7/2026 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch names, commit SHAs, commit messages, and… | |
| Aplazada | Alta (8.6) | 0.75% | — | Github Enterprise ServerAI | 17/7/2026 | 17/7/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the path validation did not check the… | |
| Aplazada | Media (5.7) | 0.64% | — | Github Enterprise ServerAI | 17/7/2026 | 17/7/2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the configuration file was parsed without a nesting… | |
| Pendiente de análisis | Baja (3.3) | 0.10% | — | HCL DfmproAIHCL DfxanalyticsAIHCL DfxserverAI | 17/7/2026 | 29/9/2026 | Los instaladores de HCL DFMPro, DFXAnalytics y DFXServer están afectados por la vulnerabilidad 'Permisos de archivo inseguros que conducen a escalada de privilegios', lo que permite a cualquier usuario no administrativo que haya iniciado sesión sobrescribir o reemplazar el archivo ejecutable con un binario malicioso. | |
| Aplazada | Media (6.5) | 0.34% | — | Proxmox Virtual EnvironmentAIProxmox Qemu-serverAI | 17/7/2026 | 17/7/2026 | Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API. | |
| Aplazada | Alta (7.2) | 0.39% | — | Proxmox Virtual EnvironmentAIProxmox Pve-managerAIProxmox Qemu-serverAIProxmox Pve-containerAI | 17/7/2026 | 17/7/2026 | A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call… | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 16/7/2026 | 22/7/2026 | Una neutralización incorrecta de la entrada durante la generación de páginas web ('secuencias de comandos en sitios cruzados' o XSS) en Microsoft Office SharePoint permite a un atacante autorizado realizar suplantación (spoofing) a través de una red. | |
| Aplazada | Media (6.1) | 0.34% | — | Apify MCP ServerAI | 16/7/2026 | 17/7/2026 | The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.9.21, the fetch-apify-docs tool in src/tools/common/fetch_apify_docs.ts validates allowlisted documentation domains with String.startsWith() rather… | |
| Analizada | Media (4.3) | 0.37% | — | Getdbt DBT MCP Server | 16/7/2026 | 21/7/2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_called_event() in src/dbt_mcp/tracking/tracking.py serialized every MCP tool call's complete arguments dictionary and sent it through dbtlabs_vortex.producer.log_proto without redaction, including… | |
| Analizada | Baja (3.3) | 0.17% | — | Getdbt DBT MCP Server | 16/7/2026 | 21/7/2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote those records to dbt-mcp.log when… | |
| Analizada | Media (6.3) | 0.21% | — | Getdbt DBT MCP Server | 16/7/2026 | 21/7/2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and resource_type values to the dbt subprocess argument list, allowing an MCP client to inject dbt global flags such as --profiles-dir,… | |
| Aplazada | Media (5.3) | 0.26% | — | Janssen Project Jans Auth ServerAI | 16/7/2026 | 16/7/2026 | The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner signature validation when jwe.getSignedJWTPayload() returns null, and AuthzRequestService.processRequestObject() does… | |
| Analizada | Alta (8.2) | 0.42% | — | Hcltech DFX Server | 16/7/2026 | 21/7/2026 | HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without… | |
| Analizada | Media (6.3) | 0.30% | — | Hcltech DFX Server | 16/7/2026 | 21/7/2026 | HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or… | |
| Analizada | Alta (8.2) | 0.43% | — | Hcltech DFX Server | 16/7/2026 | 21/7/2026 | HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials. | |
| Analizada | Media (6.3) | 0.19% | — | Hcltech DFX Server | 16/7/2026 | 21/7/2026 | HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application. | |
| Analizada | Crítica (9.6) | 0.48% | — | Broadcom Spring Authorization Server | 16/7/2026 | 4/9/2026 | Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10. | |
| Pendiente de análisis | Alta (7.5) | 0.89% | — | Feast Feature ServerAI | 16/7/2026 | 16/7/2026 | A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resources—such as memory, CPU, and file… |