Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3077▲ 492 respecto a la semana anterior
Críticas / altas1455▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

25.937 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.15%—Nixpkgs MysqlAINixpkgs Percona-serverAI15/7/202615/7/2026
Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the MySQL database in a way that allows local users, such as unprivileged web or CGI processes on the same host, to log in…
Pendiente de análisisAlta (8.6)0.53%💥 PoCGrafana MCP ServerAI15/7/202615/7/2026
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.
AplazadaMedia (6.5)0.52%—Caxperts Universalplantviewer Webservices ServerAI14/7/202615/7/2026
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver.
AplazadaCrítica (9.1)0.55%—Andreimarcu Linux-serverAI14/7/202615/7/2026
An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go
AplazadaAlta (7.5)0.31%💥 PoCAndreimarcu Linux-serverAI14/7/202615/7/2026
Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the uploadPutHandler function
Pendiente de análisisCrítica (9.2)0.39%—Amazon Healthlake-mcp-serverAI14/7/202615/7/2026
AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a…
AplazadaAlta (7.5)0.49%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service.
AplazadaMedia (6.5)0.44%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
AplazadaAlta (7.5)0.49%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.5)0.49%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.5)0.53%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.5)0.53%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaAlta (7.5)0.54%—Nvidia Triton Inference Server14/7/20264/9/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaBaja (3.3)0.15%—Devolutions Server14/7/202615/7/2026
Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is…
AnalizadaAlta (7.1)0.29%—Devolutions Server14/7/202630/7/2026
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.
AnalizadaAlta (7.5)0.25%—Devolutions Server14/7/202630/7/2026
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier.
AnalizadaBaja (3.1)0.21%—Devolutions Server14/7/202630/7/2026
Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.
AnalizadaMedia (5.5)0.24%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+814/7/202622/7/2026
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+814/7/202622/7/2026
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+714/7/202622/7/2026
Un uso después de liberar (use-after-free) en Windows Win32K permite a un atacante autorizado elevar privilegios localmente.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+914/7/202629/7/2026
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.20%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+514/7/202622/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)1.2%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+314/7/202617/7/2026
Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (8.8)0.91%—Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+314/7/202622/7/2026
Un uso después de liberar (use-after-free) en Windows Remote Desktop Services permite a un atacante autorizado ejecutar código a través de una red.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+714/7/202622/7/2026
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.