Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3238▲ 694 respecto a la semana anterior
Críticas / altas1520▲ 133 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

25.772 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.3)0.32%—Github Enterprise Server30/6/20262/7/2026
A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The AnsweredQuestionStructuredDataComponent did not…
AnalizadaMedia (6)0.41%—Github Enterprise Server30/6/20262/7/2026
—
AnalizadaMedia (4.8)0.36%—Github Enterprise Server30/6/20262/7/2026
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to…
AnalizadaMedia (6.1)0.34%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.
AnalizadaAlta (7.5)0.45%—IBM Infosphere Information Server30/6/20262/7/2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.
AnalizadaAlta (7.5)0.47%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
ModificadaCrítica (9.8)0.36%—IBM Websphere Application Server30/6/20266/8/2026
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
AnalizadaCrítica (9.3)0.38%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
AnalizadaCrítica (9.3)0.38%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
AnalizadaAlta (7.5)0.78%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.
AnalizadaCrítica (9.8)0.40%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
AplazadaAlta (7)0.43%—Promod VAIDigipede ServerAI30/6/202630/6/2026
PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.
AplazadaAlta (7.5)0.55%—Technitium DNS ServerAI26/6/20265/7/2026
An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll, TechnitiumLibrary.Net/Dns/DnsClient.cs components
AplazadaMedia (6)0.21%—Github MCP ServerAI26/6/202627/6/2026
GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton initialized with the first authenticated user's GraphQL client. All subsequent requests from different users share this…
AnalizadaMedia (6.5)0.14%—Mattermost Server26/6/202629/6/2026
Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SSRF) and exfiltrate…
AnalizadaBaja (3.5)0.27%—Mattermost Server26/6/202629/6/2026
Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate data to an attacker-controlled server via injecting markdown image syntax into tool result content…
AnalizadaMedia (6.1)0.38%—Revive-adserver Revive Adserver26/6/202629/6/2026
A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encoded nor sanitised, allowing user‑supplied input to be reflected without…
AnalizadaMedia (4.3)0.29%—Revive-adserver Revive Adserver26/6/202629/6/2026
A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the method correctly returned an error, the associated session was not invalidated. As a result, the leaked session ID could be…
AnalizadaMedia (5.4)0.34%—Revive-adserver Revive Adserver26/6/202629/6/2026
A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is executed when an administrator uses the…
AnalizadaAlta (8.8)4.9%—Revive-adserver Revive Adserver26/6/202629/6/2026
Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or using the `ox.setChannelTargeting` XML-RPC API method.
AnalizadaMedia (5.4)0.38%—Revive-adserver Revive Adserver26/6/20268/7/2026
A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.
AnalizadaMedia (4.3)0.49%—Revive-adserver Revive Adserver26/6/202629/6/2026
A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campaigns.php` script in Revive Adserver 6.0.7 and earlier. As a result, a low‑privileged user could link their trackers to campaigns owned by…
AplazadaAlta (7.7)0.18%—Parseplatform Parse ServerAI25/6/202626/6/2026
Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based…
AnalizadaAlta (7.7)0.18%—Parseplatform Parse-server25/6/202630/7/2026
Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.
AnalizadaBaja (2.3)0.46%—Bitwarden Server25/6/202614/7/2026
Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding. When an organization has configured an event integration whose template references a user-controlled…