Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

375 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (8.8)——Emilia Progress PlannerAI6/10/20266/10/2026
Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions.
RecibidaAlta (7.1)——ProgressifyAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Progressify - Progressive Web App (PWA) <= 1.6.0 versions.
RecibidaAlta (8.8)——Progress Sitefinity Nextjs SDKAI5/10/20266/10/2026
CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.
RecibidaAlta (7.9)——Progress Telerik Fiddler ClassicAI5/10/20265/10/2026
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a valid Authenticode signature whose…
RecibidaMedia (6.6)——Progress Fiddler ClassicAI5/10/20265/10/2026
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Fiddler writes the certificate to a temporary file in a…
RecibidaBaja (3.6)——Progress Telerik Fiddler ClassicAI5/10/20265/10/2026
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames…
RecibidaMedia (6.3)——Progress Fiddler ClassicAI5/10/20265/10/2026
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Content-Length headers with conflicting values are forwarded verbatim to the origin server, while Fiddler frames the request…
Pendiente de análisisAlta (7.7)0.09%—Progress Software Fiddler EverywhereAI29/9/202630/9/2026
Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.
Pendiente de análisisMedia (5.6)0.12%—Progress Telerik Fiddler EverywhereAI29/9/202630/9/2026
Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful…
AplazadaMedia (4.3)0.16%—Ninja Forms Save ProgressAI5/9/20268/9/2026
The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and…
Pendiente de análisisAlta (8.1)0.16%—Progress Telerik UI FOR AjaxAIProgress RadaditorAI2/9/20268/9/2026
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into,…
Pendiente de análisisAlta (7.5)0.36%—Progress Telerik UI FOR AjaxAI2/9/20268/9/2026
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.
AnalizadaAlta (7.2)0.94%—Progress Sharefile Storage Zones Controller17/8/20262/9/2026
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5…
AnalizadaAlta (8)0.83%—Progress Sharefile Storage Zones Controller17/8/20262/9/2026
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.
AnalizadaAlta (7.2)0.74%—Progress Sharefile Storage Zones Controller17/8/20262/9/2026
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of…
AnalizadaAlta (8.8)0.68%—Progress Whatsup Gold12/8/20262/9/2026
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
AnalizadaMedia (6.8)0.35%—Progress Whatsup Gold12/8/20262/9/2026
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
AnalizadaMedia (6.8)0.38%—Progress Whatsup Gold12/8/20262/9/2026
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
AnalizadaMedia (4.3)0.25%—Progress Whatsup Gold12/8/20262/9/2026
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
AnalizadaAlta (8)0.41%—Progress Whatsup Gold12/8/20262/9/2026
In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.
AnalizadaAlta (8.5)0.34%—Progress Marklogic Server5/8/20263/9/2026
A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the…
AnalizadaCrítica (9.3)0.65%—Progress Marklogic Server5/8/20263/9/2026
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions…
AnalizadaCrítica (9.9)0.46%—Progress Marklogic Server5/8/20263/9/2026
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
AnalizadaCrítica (9.8)0.83%—Progress Marklogic Server5/8/20263/9/2026
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
AnalizadaCrítica (9.1)0.74%—Progress Marklogic Server5/8/20263/9/2026
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing…