Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.8) | 0.47% | — | Mitre SAF HeimdallAITenableAI | 29/8/2026 | 1/9/2026 | In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts. | |
| Aplazada | Alta (7.2) | 1.3% | — | Heimdall Data Database ProxyAI | 20/8/2026 | 1/9/2026 | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within the… | |
| Pendiente de análisis | Alta (7.2) | 1.1% | — | Heimdall Data Database ProxyAI | 29/7/2026 | 30/7/2026 | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within… | |
| Aplazada | Alta (7.8) | 0.54% | — | Dadrus HeimdallAI | 8/5/2026 | 17/6/2026 | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request path, while downstream components may normalize dot-segments according to RFC 3986, Section 6.2.2.3. This discrepancy can result in heimdall… | |
| Aplazada | Alta (7.8) | 0.52% | — | Dadrus HeimdallAI | 8/5/2026 | 17/6/2026 | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs host matching in a case-sensitive manner, while HTTP hostnames are case-insensitive. This discrepancy can result in heimdall failing to match a rule for a request host that differs only in… | |
| Aplazada | Alta (7.8) | 0.55% | — | Dadrus HeimdallAI | 8/5/2026 | 17/6/2026 | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-sensitive manner, while percent-encoding is defined to be case-insensitive. As a result, the lowercase equivalent (%2f) is not recognized and therefore not… | |
| Analizada | Alta (7.5) | 0.42% | — | Dadrus Heimdall | 20/3/2026 | 17/6/2026 | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. When using Heimdall in envoy gRPC decision API mode with versions 0.7.0-alpha through 0.17.10, wrong encoding of the query URL string allows rules with non-wildcard path expressions to be bypassed. Envoy splits the requested URL into… | |
| Aplazada | Alta (8.8) | 0.45% | — | Heimdall Data Database ProxyAI | 6/11/2025 | 17/6/2026 | Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Crítica (9.8) | 2.8% | — | Linuxserver Docker-heimdall | 30/7/2025 | 17/6/2026 | LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external… | |
| Analizada | Media (6.1) | 0.56% | — | Linuxserver Heimdall Application Dashboard | 27/7/2025 | 17/6/2026 | LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter. | |
| Aplazada | Baja (2.8) | 0.17% | — | Heimdalsecurity ThorAI | 20/7/2025 | 17/6/2026 | Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments." | |
| Aplazada | Crítica (9.8) | 0.70% | — | Linuxserver HeimdallAI | 1/4/2024 | 17/6/2026 | LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring. | |
| Modificada | Crítica (9.1) | 0.66% | — | Heimdalsecurity Thor | 21/12/2023 | 17/6/2026 | An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to cause a denial of service (DoS) via the Threat To Process Correlation threat prevention module. NOTE: Heimdal asserts this is not a valid vulnerability. Their DNS Security for Endpoint… | |
| Modificada | Crítica (9.8) | 1.0% | — | Heimdalsecurity Thor | 21/12/2023 | 17/6/2026 | An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sensitive information via Next-Gen Antivirus component. NOTE: Heimdal argues that the limitation described here is a Microsoft Windows issue,… | |
| Modificada | Crítica (9.8) | 0.95% | — | Heimdalsecurity Thor | 21/12/2023 | 17/6/2026 | An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to bypass network filtering, execute arbitrary code, and obtain sensitive information via DarkLayer Guard threat prevention module. NOTE: Heimdal disputes the validity of this issue… | |
| Modificada | Alta (7.5) | 0.89% | — | Heimdal Project Heimdal | 27/3/2023 | 17/6/2026 | The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash. | |
| Modificada | Alta (7.5) | 0.49% | — | Heimdal Project Heimdal | 6/3/2023 | 17/6/2026 | The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the… | |
| Modificada | Media (5.4) | 0.40% | — | Linuxserver Heimdall Application Dashboard | 27/12/2022 | 17/6/2026 | Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page. | |
| Modificada | Alta (7.5) | 1.2% | — | Heimdal Project Heimdal | 26/12/2022 | 17/6/2026 | Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept. | |
| Modificada | Alta (8.8) | 6.2% | — | MIT Kerberos 5Heimdal Project HeimdalSamba | 25/12/2022 | 17/6/2026 | PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other… | |
| Modificada | Crítica (9.8) | 1.8% | — | Heimdal Project HeimdalSamba | 25/12/2022 | 17/6/2026 | Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC). | |
| Modificada | Alta (7.5) | 0.97% | — | Heimdal Project HeimdalDebian Linux | 15/11/2022 | 17/6/2026 | Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) and kinit (via PKINIT), as well as any third-party applications using Heimdal's libhx509. Users… | |
| Modificada | Alta (7.8) | 0.25% | — | Heimdalsecurity Heimdal Premium Security | 10/3/2022 | 9/7/2026 | Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer. | |
| Modificada | Alta (7.5) | 2.5% | — | SambaHeimdal Project Heimdal | 31/7/2019 | 17/6/2026 | A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the… | |
| Modificada | Alta (7.4) | 2.0% | — | Heimdal Project HeimdalFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+1 | 15/5/2019 | 17/6/2026 | In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c. |