Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.63% | — | Graylog ServerAIGraylog ForwarderAI | 28/8/2026 | 9/9/2026 | Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFortiGateSyslogEvent.java and… | |
| Modificada | Alta (8.5) | 0.33% | — | Nagios LOG Server | 17/11/2025 | 17/6/2026 | Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directories. The 'www-data' user is a member of the 'nagios' group, which has write access to '/usr/local/nagioslogserver/scripts', while several… | |
| Modificada | Alta (8.6) | 9.5% | — | Nagios LOG Server | 17/11/2025 | 17/6/2026 | Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature. When this feature is configured, certain user-controlled settings—including model selection and connection parameters—are read from the global configuration… | |
| Analizada | Alta (8.7) | 0.70% | — | Nagios LOG Server | 30/10/2025 | 17/6/2026 | Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent account state that… | |
| Analizada | Crítica (9.4) | 2.2% | — | Nagios LOG Server | 30/10/2025 | 17/6/2026 | Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an internal API. An attacker able to supply crafted dashboard ID values can cause the system to execute attacker-controlled data, leading to… | |
| Analizada | Crítica (9.3) | 2.1% | — | Nagios LOG Server | 30/10/2025 | 17/6/2026 | Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash process as the root user. If an attacker is able to compromise the Logstash process - for example by exploiting an insecure plugin, pipeline configuration injection, or a… | |
| Analizada | Alta (7.1) | 1.0% | — | Nagios LOG Server | 30/10/2025 | 17/6/2026 | Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global dashboards. The application did not correctly enforce authorization checks for the global dashboard deletion workflow, enabling lower-privileged users to remove… | |
| Analizada | Media (5.3) | 0.86% | — | Nagios LOG Server | 30/10/2025 | 17/6/2026 | In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard being presented as the user's default view. Depending on the product's… | |
| Analizada | Alta (8.7) | 0.74% | — | Nagios LOG Server | 30/10/2025 | 17/6/2026 | Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network path can intercept… | |
| Analizada | Media (6.9) | 0.63% | — | Nagios LOG Server | 30/10/2025 | 17/6/2026 | Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface, logs, or other diagnostic output. This can… | |
| Analizada | Media (5.1) | 0.51% | — | Nagios LOG Server | 30/10/2025 | 17/6/2026 | Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Create User function. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser. | |
| Analizada | Alta (8.7) | 1.1% | — | Nagios LOG Server | 30/10/2025 | 17/6/2026 | Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API endpoints, resulting in unintended access to data and actions exposed via the API. This incorrect authorization check could allow authenticated… | |
| Analizada | Media (5.1) | 0.51% | — | Nagios LOG Server | 30/10/2025 | 17/6/2026 | Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the Snapshots Page. Untrusted log content was not safely encoded for the output context, allowing attacker-controlled data present in logs to execute script in the victim’s browser within the application origin. | |
| Analizada | Media (5.1) | 0.51% | — | Nagios LOG Server | 30/10/2025 | 17/6/2026 | Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and Manage Host Lists pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a… | |
| Analizada | Media (5.1) | 0.51% | — | Nagios LOG Server | 30/10/2025 | 17/6/2026 | Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when rendering log entries in the Logs table. Untrusted log content was not safely encoded for the output context, allowing attacker-controlled data present in logs to execute script in the victim’s browser… | |
| Analizada | Alta (8.5) | 0.28% | — | Nagios LOG Server | 30/10/2025 | 1/10/2026 | Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web user (or the backend shell user) to escalate to root on the host. | |
| Analizada | Media (6.5) | 2.8% | — | Nagios LOG Server | 7/10/2025 | 17/6/2026 | Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/index.php/api/system/stop?subsystem=elasticsearch call. The service stops even though "message": "Could not stop elasticsearch" is in the API response. This is GL:NLS#474. | |
| Analizada | Alta (8.8) | 16% | — | Nagios LOG Server | 7/10/2025 | 17/6/2026 | Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475. | |
| Analizada | Media (5.3) | 0.21% | — | Checkpoint LOG Server | 6/8/2025 | 17/6/2026 | Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs | |
| Analizada | Alta (8.3) | 7.2% | — | Nagios LOG Server | 15/4/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field. | |
| Aplazada | Media (5.7) | 9.9% | — | Klogserver Klog ServerAI | 18/2/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls. This issue affects KLog Server: before 3.1.1. | |
| Modificada | Media (4.3) | 0.96% | — | Solarwinds Kiwi Syslog Server | 29/10/2021 | 17/6/2026 | A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an actionable item, such as a button or link, to another server in which they have… | |
| Modificada | Media (5.3) | 0.52% | — | Solarwinds Kiwi Syslog Server | 27/10/2021 | 17/6/2026 | The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HTTPS. This will help protect the cookie from being passed over unencrypted requests. If the… | |
| Modificada | Media (5.3) | 1.3% | — | Solarwinds Kiwi Syslog Server | 27/10/2021 | 17/6/2026 | The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Debug mode causes ASP.NET to compile applications with extra information. The information enables a debugger to closely monitor and control the… | |
| Modificada | Media (5.3) | 0.96% | — | Solarwinds Kiwi Syslog Server | 27/10/2021 | 17/6/2026 | The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by returning exact HTTP request that was received in the response to the client. This may lead to the… |