Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3077▲ 492 respecto a la semana anterior
Críticas / altas1455▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
25.937 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.15% | — | Nixpkgs MysqlAINixpkgs Percona-serverAI | 15/7/2026 | 15/7/2026 | Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the MySQL database in a way that allows local users, such as unprivileged web or CGI processes on the same host, to log in… | |
| Pendiente de análisis | Alta (8.6) | 0.53% | 💥 PoC | Grafana MCP ServerAI | 15/7/2026 | 15/7/2026 | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints. | |
| Aplazada | Media (6.5) | 0.52% | — | Caxperts Universalplantviewer Webservices ServerAI | 14/7/2026 | 15/7/2026 | Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver. | |
| Aplazada | Crítica (9.1) | 0.55% | — | Andreimarcu Linux-serverAI | 14/7/2026 | 15/7/2026 | An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go | |
| Aplazada | Alta (7.5) | 0.31% | 💥 PoC | Andreimarcu Linux-serverAI | 14/7/2026 | 15/7/2026 | Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the uploadPutHandler function | |
| Pendiente de análisis | Crítica (9.2) | 0.39% | — | Amazon Healthlake-mcp-serverAI | 14/7/2026 | 15/7/2026 | AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a… | |
| Aplazada | Alta (7.5) | 0.49% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Media (6.5) | 0.44% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Aplazada | Alta (7.5) | 0.49% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (7.5) | 0.49% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (7.5) | 0.53% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (7.5) | 0.53% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Alta (7.5) | 0.54% | — | Nvidia Triton Inference Server | 14/7/2026 | 4/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Baja (3.3) | 0.15% | — | Devolutions Server | 14/7/2026 | 15/7/2026 | Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is… | |
| Analizada | Alta (7.1) | 0.29% | — | Devolutions Server | 14/7/2026 | 30/7/2026 | Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review. | |
| Analizada | Alta (7.5) | 0.25% | — | Devolutions Server | 14/7/2026 | 30/7/2026 | Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier. | |
| Analizada | Baja (3.1) | 0.21% | — | Devolutions Server | 14/7/2026 | 30/7/2026 | Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier. | |
| Analizada | Media (5.5) | 0.24% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+8 | 14/7/2026 | 22/7/2026 | Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 14/7/2026 | 22/7/2026 | Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+7 | 14/7/2026 | 22/7/2026 | Un uso después de liberar (use-after-free) en Windows Win32K permite a un atacante autorizado elevar privilegios localmente. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 14/7/2026 | 29/7/2026 | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.20% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+5 | 14/7/2026 | 22/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+3 | 14/7/2026 | 17/7/2026 | Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (8.8) | 0.91% | — | Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+3 | 14/7/2026 | 22/7/2026 | Un uso después de liberar (use-after-free) en Windows Remote Desktop Services permite a un atacante autorizado ejecutar código a través de una red. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+7 | 14/7/2026 | 22/7/2026 | Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |