Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3248▲ 704 respecto a la semana anterior
Críticas / altas1521▲ 136 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

25.772 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.29%—Linuxfoundation Nats-server8/7/20269/7/2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered as the configured no_auth_user through a parser path used when the first client operation was not CONNECT, bypassing user-level connection restrictions such as…
AnalizadaAlta (7.5)0.60%—Linuxfoundation Nats-server8/7/20269/7/2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket…
AnalizadaMedia (6.5)0.56%—Linuxfoundation Nats-server8/7/20269/7/2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server by supplying Connz pagination Offset and Limit values that overflowed internal arithmetic before the…
AplazadaBaja (2.3)0.53%—Parseplatform Parse ServerAI8/7/202610/7/2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field and the subscriber's ACL read access,…
AplazadaAlta (8.7)0.59%—Parseplatform Parse ServerAI8/7/202610/7/2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply nested $or, $and, and $nor query condition operators in the REST API or LiveQuery query handling could trigger exponential-time processing in the internal query-traversal…
AnalizadaCrítica (9.3)0.37%—Bitwarden Server8/7/202620/7/2026
Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication…
AnalizadaMedia (5.3)0.31%—Linuxfoundation Nats-server8/7/202613/7/2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were applied to ordinary client connections but not consistently to messages arriving through leafnode connections, allowing a leafnode operator to send trace…
AnalizadaAlta (8.8)0.37%—Linuxfoundation Nats-server8/7/202613/7/2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client connections could also apply to route or leafnode listeners, allowing an unauthenticated peer to…
AnalizadaMedia (6.5)0.46%—Linuxfoundation Nats-server8/7/202613/7/2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user could receive messages on denied subjects when a wildcard subscription overlapped with a configured wildcard deny rule but was not a subset of it, and queue…
AnalizadaMedia (6.5)0.46%—Linuxfoundation Nats-server8/7/202613/7/2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain subject deny rule by using a queue subscription, because queue-specific deny evaluation could override…
AnalizadaAlta (7.5)0.74%—Linuxfoundation Nats-server8/7/202613/7/2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication leafnode handshake by sending repeated leafnode…
AnalizadaMedia (4.3)0.35%—Linuxfoundation Nats-server8/7/202613/7/2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject family, bypassing configured subscribe permissions and exposing MQTT QoS2 protocol metadata for…
AnalizadaAlta (7.1)0.44%—Linuxfoundation Nats-server8/7/202613/7/2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as NATS protocol data to route or leafnode connections, corrupting the forwarded…
AnalizadaAlta (7.5)0.74%—Linuxfoundation Nats-server8/7/202613/7/2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQTT client could cause the server to retain large incomplete MQTT CONNECT packets before authentication completed, consuming server memory while the parser waited for the…
AnalizadaMedia (4.3)0.34%—Linuxfoundation Nats-server8/7/202613/7/2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule because these delivery paths did not…
AplazadaAlta (7.6)0.31%—Midscene Bridge ServerAI8/7/20268/10/2026
Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows unauthenticated remote attackers to hijack active bridge sessions by opening a cross-origin WebSocket connection to the local Socket.IO server, which performs no Origin…
AnalizadaMedia (6.9)0.45%—Openvpn Access Server8/7/202629/9/2026
OpenVPN Access Server 2.7.2 hasta 3.1.0 acepta secuencias de salto de línea desnudas dentro de los valores de encabezado HTTP, lo que permite a atacantes remotos realizar contrabando de solicitudes HTTP cuando se implementa detrás de un proxy inverso.
AnalizadaAlta (7.5)0.46%—Tanium Server8/7/202610/7/2026
Tanium addressed a denial of service vulnerability in Tanium Server.
AnalizadaBaja (3.7)0.36%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux8/7/20269/7/2026
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though…
AnalizadaCrítica (9)0.31%—X.org X ServerX.org Xwayland8/7/20269/7/2026
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
AnalizadaAlta (7.8)0.33%—X.org X ServerX.org Xwayland8/7/20269/7/2026
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
AplazadaMedia (4.3)0.34%—Actual APP Sync ServerAI7/7/20268/7/2026
Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ handler enforces an admin check in OpenID mode. Any authenticated…
AnalizadaMedia (4.4)0.11%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux7/7/20269/7/2026
A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.
AnalizadaMedia (5.3)0.49%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux7/7/20269/7/2026
A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the end of a heap allocation while sorting RDN attribute-value pairs. An…
Pendiente de análisisMedia (4.8)0.42%💥 PoCDigi Portserver TSAIDigi ONE SPAIDigi ONE SP IAAIDigi ONE IAAI7/7/202613/7/2026
A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who…