Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.63% | — | Outsystems Platform Server | 9/12/2025 | 24/8/2026 | Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the body length. NOTE: the Supplier indicates that they are unable to reproduce this. | |
| Aplazada | Alta (7.1) | 0.34% | — | Angular Platform ServerAIAngular SSRAI | 10/9/2025 | 17/6/2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Angular uses a DI container (the "platform injector") to hold request-specific state during server-side rendering. For historical reasons, the container was stored as a JavaScript… | |
| Modificada | Alta (7.5) | 2.3% | — | Tibco Managed File Transfer Platform Server | 30/3/2022 | 17/6/2026 | The cfsend, cfrecv, and CyberResp components of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UNIX and TIBCO Managed File Transfer Platform Server for z/Linux contain a difficult to exploit Remote Code Execution (RCE) vulnerability that allows a low privileged attacker with network access to… | |
| Modificada | Media (6.1) | 0.82% | — | Outsystems Lifetime Management ConsoleOutsystemsOutsystems Platform Server | 31/8/2021 | 17/6/2026 | A stored XSS vulnerability was discovered in the ECT Provider in OutSystems before 2020-09-04, affecting generated applications. It could allow an unauthenticated remote attacker to craft and store malicious Feedback content into /ECT_Provider/, such that when the content is viewed (it can only be viewed by… | |
| Modificada | Alta (8.6) | 0.95% | — | Outsystems Lifetime Management ConsoleOutsystemsOutsystems Platform Server | 12/4/2021 | 17/6/2026 | The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) allows SSRF for arbitrary outbound HTTP requests. | |
| Modificada | Crítica (9.8) | 2.3% | — | Tibco Managed File Transfer Platform Server | 9/6/2020 | 17/6/2026 | The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows execution of arbitrary commands at the privilege level of the affected system following a failed file transfer. Affected releases are TIBCO Software Inc.'s TIBCO… | |
| Modificada | Crítica (9.8) | 1.4% | — | Tibco Managed File Transfer Platform Server | 9/6/2020 | 17/6/2026 | The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows an attacker to perform unauthorized network file transfers to and from the file system accessible to the affected component. This vulnerability is exploitable… |