Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.73% | — | OGXAI | 4/9/2026 | 23/9/2026 | OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses endpoint. MCP tool definitions accept a server_url parameter (along with headers and authorization values) that is fetched server-side without… | |
| Aplazada | Media (4.3) | 0.15% | — | CatalogxAI | 2/9/2026 | 3/9/2026 | The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an… | |
| Aplazada | Alta (7.1) | 0.22% | — | Ptibogxiv DoliconnectAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ptibogxiv Doliconnect doliconnect allows Reflected XSS.This issue affects Doliconnect: from n/a through <= 9.3.2. | |
| Aplazada | Alta (7.1) | 0.13% | — | Ptibogxiv DoliconnectAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ptibogxiv Doliconnect doliconnect allows Stored XSS.This issue affects Doliconnect: from n/a through <= 9.5.7. | |
| Modificada | Alta (10) | 8.4% | — | Analogx Simpleserver WWW | 12/2/2010 | 16/6/2026 | Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vulnerability than CVE-2000-0664. | |
| Modificada | Alta (10) | 6.8% | — | Analogx Proxy | 30/6/2003 | 16/6/2026 | Buffer overflow in AnalogX Proxy 4.13 allows remote attackers to execute arbitrary code via a long URL to port 6588. | |
| Modificada | Alta (7.5) | 6.5% | — | Analogx Proxy | 4/10/2002 | 16/6/2026 | Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long HTTP request to TCP port 6588 or (2) a SOCKS 4A request to TCP port 1080 with a long DNS hostname. | |
| Modificada | Alta (7.5) | 6.5% | — | Analogx Simpleserver WWW | 4/10/2002 | 16/6/2026 | Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long HTTP request method name. | |
| Modificada | Alta (7.5) | 3.3% | — | Analogx Simpleserver Shout | 4/10/2002 | 16/6/2026 | Buffer overflow in AnalogX SimpleServer:Shout 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long request to TCP port 8001. | |
| Modificada | Media (5) | 3.3% | — | Analogx Simpleserver WWW | 2/7/2001 | 16/6/2026 | AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory. | |
| Modificada | Media (5) | 7.9% | — | Analogx Simpleserver WWW | 26/7/2000 | 16/6/2026 | AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL encoding for the dots. | |
| Modificada | Media (5) | 2.0% | — | Analogx Proxy | 25/7/2000 | 16/6/2026 | Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long HELO command in the SMTP protocol. | |
| Modificada | Media (5) | 9.0% | — | Analogx Proxy | 25/7/2000 | 16/6/2026 | Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP protocol. | |
| Modificada | Media (5) | 1.4% | — | Analogx Proxy | 25/7/2000 | 16/6/2026 | Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long user ID in a SOCKS4 CONNECT request. | |
| Modificada | Media (5) | 1.9% | — | Analogx Proxy | 25/7/2000 | 16/6/2026 | Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the POP3 protocol. | |
| Modificada | Alta (7.5) | 2.6% | — | Analogx Simpleserver WWW | 15/6/2000 | 16/6/2026 | Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory. | |
| Modificada | Media (5) | 7.3% | — | Analogx Simpleserver WWW | 25/3/2000 | 16/6/2026 | AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin. | |
| Modificada | Alta (7.5) | 9.4% | — | Analogx Simpleserver WWW | 31/12/1999 | 16/6/2026 | Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET request. |