Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.35% | — | TON Lite ServerAI | 13/2/2026 | 17/6/2026 | A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises from the handling of external arguments passed to locally executed "get methods." An attacker can inject a constructed Continuation object (an internal TVM type) that is normally restricted within… | |
| Aplazada | Baja (2.1) | 0.24% | — | Isaacwasserman MCP Vegalite ServerAI | 6/2/2026 | 17/6/2026 | A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vulnerability is the function eval of the component visualize_data. Such manipulation of the argument vegalite_specification leads to code injection. The attack may be… | |
| Modificada | Alta (7.5) | 1.2% | — | Lite-server Project Lite-server | 20/12/2022 | 17/6/2026 | All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse. | |
| Modificada | Media (4.9) | 1.6% | — | Oracle Database Mobile/lite Server | 21/10/2015 | 17/6/2026 | Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server 10.3.0.3, 11.3.0.2, and 12.1.0.0 allows remote authenticated users to affect integrity and availability via unknown vectors. | |
| Modificada | Alta (10) | 2.5% | — | Oracle Database Mobile/lite Server | 17/1/2013 | 16/6/2026 | Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-0361. | |
| Modificada | Alta (7.8) | 1.7% | — | Oracle Database LiteOracle Database Mobile/lite Server | 17/1/2013 | 16/6/2026 | Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0362 and CVE-2013-0363. | |
| Modificada | Alta (7.8) | 1.7% | — | Oracle Database Mobile/lite Server | 17/1/2013 | 16/6/2026 | Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0362 and CVE-2013-0364. | |
| Modificada | Alta (7.8) | 1.5% | — | Oracle Database Mobile/lite Server | 17/1/2013 | 16/6/2026 | Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0363 and CVE-2013-0364. | |
| Modificada | Alta (10) | 2.5% | — | Oracle Database LiteOracle Database Mobile/lite Server | 17/1/2013 | 16/6/2026 | Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-0366. | |
| Modificada | Media (6.8) | 0.82% | — | Redhat Network Satellite ServerRedhat Spacewalk-java | 27/7/2011 | 16/6/2026 | A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or escalating privileges by modifying… | |
| Modificada | Media (6.4) | 1.7% | — | Redhat Network Satellite Server | 18/4/2011 | 16/6/2026 | Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors. | |
| Modificada | Media (5.8) | 1.3% | — | Redhat Network Satellite Server | 25/2/2011 | 16/6/2026 | Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to conduct brute force password guessing attacks. | |
| Modificada | Media (5.8) | 2.0% | — | Redhat Network Satellite Server | 25/2/2011 | 16/6/2026 | Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors related to Spacewalk. | |
| Modificada | Media (6.5) | 2.4% | — | Redhat Network Satelite Server | 30/8/2007 | 16/6/2026 | Unspecified vulnerability in Red Hat Network Satellite Server 5.0.0 allows remote authenticated users to execute arbitrary code via unknown vectors in a "back-end XMLRPC handler." |