Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▲ 218 respecto a la semana anterior
Críticas / altas1330▼ 103 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

25.772 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.52%—Open Event ServerAI17/7/202617/7/2026
Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submitting requests to the group followers CSV export endpoint which lacks any…
AplazadaMedia (5.3)0.45%—Github Enterprise ServerAI17/7/202617/7/2026
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch names, commit SHAs, commit messages, and…
AplazadaAlta (8.6)0.75%—Github Enterprise ServerAI17/7/202617/7/2026
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the path validation did not check the…
AplazadaMedia (5.7)0.64%—Github Enterprise ServerAI17/7/202617/7/2026
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the configuration file was parsed without a nesting…
Pendiente de análisisBaja (3.3)0.10%—HCL DfmproAIHCL DfxanalyticsAIHCL DfxserverAI17/7/202629/9/2026
Los instaladores de HCL DFMPro, DFXAnalytics y DFXServer están afectados por la vulnerabilidad 'Permisos de archivo inseguros que conducen a escalada de privilegios', lo que permite a cualquier usuario no administrativo que haya iniciado sesión sobrescribir o reemplazar el archivo ejecutable con un binario malicioso.
AplazadaMedia (6.5)0.34%—Proxmox Virtual EnvironmentAIProxmox Qemu-serverAI17/7/202617/7/2026
Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API.
AplazadaAlta (7.2)0.39%—Proxmox Virtual EnvironmentAIProxmox Pve-managerAIProxmox Qemu-serverAIProxmox Pve-containerAI17/7/202617/7/2026
A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call…
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server16/7/202622/7/2026
Una neutralización incorrecta de la entrada durante la generación de páginas web ('secuencias de comandos en sitios cruzados' o XSS) en Microsoft Office SharePoint permite a un atacante autorizado realizar suplantación (spoofing) a través de una red.
AplazadaMedia (6.1)0.34%—Apify MCP ServerAI16/7/202617/7/2026
The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.9.21, the fetch-apify-docs tool in src/tools/common/fetch_apify_docs.ts validates allowlisted documentation domains with String.startsWith() rather…
AnalizadaMedia (4.3)0.37%—Getdbt DBT MCP Server16/7/202621/7/2026
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_called_event() in src/dbt_mcp/tracking/tracking.py serialized every MCP tool call's complete arguments dictionary and sent it through dbtlabs_vortex.producer.log_proto without redaction, including…
AnalizadaBaja (3.3)0.17%—Getdbt DBT MCP Server16/7/202621/7/2026
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote those records to dbt-mcp.log when…
AnalizadaMedia (6.3)0.21%—Getdbt DBT MCP Server16/7/202621/7/2026
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and resource_type values to the dbt subprocess argument list, allowing an MCP client to inject dbt global flags such as --profiles-dir,…
AplazadaMedia (5.3)0.26%—Janssen Project Jans Auth ServerAI16/7/202616/7/2026
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner signature validation when jwe.getSignedJWTPayload() returns null, and AuthzRequestService.processRequestObject() does…
AnalizadaAlta (8.2)0.42%—Hcltech DFX Server16/7/202621/7/2026
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without…
AnalizadaMedia (6.3)0.30%—Hcltech DFX Server16/7/202621/7/2026
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or…
AnalizadaAlta (8.2)0.43%—Hcltech DFX Server16/7/202621/7/2026
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials.
AnalizadaMedia (6.3)0.19%—Hcltech DFX Server16/7/202621/7/2026
HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.
AnalizadaCrítica (9.6)0.48%—Broadcom Spring Authorization Server16/7/20264/9/2026
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.
Pendiente de análisisAlta (7.5)0.89%—Feast Feature ServerAI16/7/202616/7/2026
A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resources—such as memory, CPU, and file…
AplazadaAlta (8.5)0.15%—Nixpkgs MysqlAINixpkgs Percona-serverAI15/7/202615/7/2026
Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the MySQL database in a way that allows local users, such as unprivileged web or CGI processes on the same host, to log in…
Pendiente de análisisAlta (8.6)0.53%💥 PoCGrafana MCP ServerAI15/7/202615/7/2026
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.
AplazadaMedia (6.5)0.52%—Caxperts Universalplantviewer Webservices ServerAI14/7/202615/7/2026
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver.
AplazadaCrítica (9.1)0.55%—Andreimarcu Linux-serverAI14/7/202615/7/2026
An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go
AplazadaAlta (7.5)0.31%💥 PoCAndreimarcu Linux-serverAI14/7/202615/7/2026
Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the uploadPutHandler function
Pendiente de análisisCrítica (9.2)0.39%—Amazon Healthlake-mcp-serverAI14/7/202615/7/2026
AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a…