Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3241▲ 698 respecto a la semana anterior
Críticas / altas1519▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
25.772 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.49% | — | 389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI | 7/7/2026 | 8/7/2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds… | |
| Modificada | Alta (8.8) | 0.43% | — | Devolutions Server | 6/7/2026 | 9/7/2026 | Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy and authenticate without completing multi-factor authentication. The problem occurs when DVLS encounters an invalid default MFA value. | |
| Modificada | Crítica (9.8) | 0.62% | — | Esri Arcgis Server | 6/7/2026 | 8/7/2026 | Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all versions of ArcGIS… | |
| Modificada | Alta (7.5) | 1.2% | — | Esri Arcgis Server | 6/7/2026 | 8/7/2026 | Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issue can allow full… | |
| Pendiente de análisis | Crítica (9.1) | 0.66% | — | Ciena Sftp ServerAI | 6/7/2026 | 8/7/2026 | An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an… | |
| Analizada | Media (6.1) | 0.25% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/7/2026 | 6/10/2026 | El software acepta entrada proporcionada por el usuario a través de un parámetro de URL sin una codificación de salida adecuada antes de reflejarla de vuelta al navegador del usuario. Esta condición permite a un atacante inyectar contenido de script malicioso en páginas servidas por la aplicación. Al aprovechar esta… | |
| Aplazada | Baja (2.1) | 0.37% | — | Aianytime Awesome-mcp-serverAI | 5/7/2026 | 6/7/2026 | A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Affected by this issue is some unknown functionality of the file mcp-wiki/src/mcp_wiki/server.py of the component mcp-wiki/wiki-summary. This manipulation of the argument url causes server-side request forgery. The… | |
| Analizada | Media (5.3) | 0.30% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+1 | 4/7/2026 | 9/7/2026 | The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to… | |
| Analizada | Alta (7.3) | 0.27% | — | Wso2 API ManagerWso2 Identity Server | 4/7/2026 | 6/10/2026 | En despliegues multi-inquilino, el mecanismo de gestión de consentimiento de aplicaciones no logra aislar correctamente los ámbitos de consentimiento entre inquilinos. El consentimiento otorgado por un usuario para una aplicación SaaS específica dentro de un inquilino puede aplicarse incorrectamente a aplicaciones… | |
| Analizada | Media (5.3) | 0.52% | — | Webpack.js Webpack-dev-server | 3/7/2026 | 7/7/2026 | webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malformed Origin header. The malformed value causes an uncaught exception in the… | |
| Analizada | Media (4.7) | 0.52% | 💥 Exploit | Webpack.js Webpack-dev-server | 3/7/2026 | 7/7/2026 | webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page. Any website a developer visits… | |
| En análisis | Media (6.1) | 0.27% | — | UI Unifi OS ServerUI Unifi Dream Machine Beast FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+26 | 2/7/2026 | 9/7/2026 | A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session. | |
| Analizada | Alta (8.8) | 0.49% | — | UI Unifi Dream Machine Beast FirmwareUI Enterprise Fortress Gateway FirmwareUI Unifi Dream Router FirmwareUI Unifi Dream Wall Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances. | |
| Analizada | Alta (8.6) | 0.77% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances. | |
| Analizada | Alta (8.8) | 1.8% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. | |
| Analizada | Alta (8.8) | 0.43% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances. | |
| Aplazada | Crítica (9.4) | 0.71% | — | Altium Enterprise ServerAIAltium 365AI | 1/7/2026 | 20/7/2026 | A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with basic git access to move arbitrary files… | |
| Analizada | Media (5.3) | 0.43% | — | Github Enterprise Server | 1/7/2026 | 6/7/2026 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. This was possible because the authorization check only verified that… | |
| Analizada | Alta (7.5) | 0.48% | — | Elastic Fleet Server | 1/7/2026 | 6/7/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable. | |
| Analizada | Alta (7.5) | 0.67% | — | Nvidia Triton Inference Server | 1/7/2026 | 6/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Alta (7.5) | 0.72% | — | Nvidia Triton Inference Server | 1/7/2026 | 6/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. A successful exploit of this vulnerability might lead to denial of service. | |
| Pendiente de análisis | Crítica (9.1) | 1.0% | — | Feast Feature ServerAI | 1/7/2026 | 15/7/2026 | A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. Although the system attempts to restrict file locations, these protections can be bypassed, enabling an attacker to… | |
| Pendiente de análisis | Crítica (9.5) | 0.42% | — | BMC Control-m ServerAI | 1/7/2026 | 1/7/2026 | A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server. This vulnerability affects… | |
| Pendiente de análisis | Alta (8.9) | 0.42% | — | BMC Control-m ServerAIBMC Control-m Enterprise ManagerAI | 1/7/2026 | 1/7/2026 | Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an authenticated attacker to trigger unintended… | |
| Modificada | Crítica (9.8) | 0.42% | — | IBM Websphere Application Server | 30/6/2026 | 29/7/2026 | IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability. |