Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 86 respecto a la semana anterior
Críticas / altas1460▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)91▼ 420 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.78% | — | Ui-tars-desktop Mcp-http-serverAIAgent-infra Mcp-server-commandsAIAgent-infra Mcp-server-filesystemAI | 27/8/2026 | 23/9/2026 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a… | |
| Pendiente de análisis | Alta (8.7) | 0.75% | — | Amazon Aws-smithy-http-serverAI | 23/7/2026 | 12/8/2026 | Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets… | |
| Analizada | Media (6.1) | 0.32% | — | Adonisjs Http-serverAdonisjs Core | 16/4/2026 | 17/6/2026 | AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server versions prior to 7.8.1 and 8.0.0-next.0 through 8.1.3, and @adonisjs/core versions prior to 7.4.0, the response.redirect().back() method reads the Referer header from the incoming HTTP request and… | |
| Modificada | Crítica (9.8) | 1.7% | — | Http-server-node Project Http-server-node | 17/12/2021 | 17/6/2026 | All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is. | |
| Modificada | Media (5.4) | 0.71% | — | Min-http-server Project Min-http-server | 30/7/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser. | |
| Modificada | Media (6.5) | 1.5% | — | Angular-http-server Project Angular-http-server | 7/6/2018 | 17/6/2026 | angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path. |