Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▲ 67 respecto a la semana anterior
Críticas / altas1456▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)92▼ 421 respecto a la semana anterior
924 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | — | — | Freedesktop Xdg-dbus-proxyAI | 2/10/2026 | 2/10/2026 | An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution… | |
| Pendiente de análisis | Media (6.1) | 0.19% | — | Oauth-proxyAI | 1/10/2026 | 1/10/2026 | A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external… | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Nginxproxymanager Nginx Proxy ManagerAI | 28/9/2026 | 30/9/2026 | Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their… | |
| Pendiente de análisis | Crítica (9.1) | 0.45% | — | Nginxproxymanager Nginx Proxy ManagerAI | 28/9/2026 | 29/9/2026 | Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session… | |
| Aplazada | Alta (7.5) | 0.26% | — | Meta ProxygenAI | 28/9/2026 | 30/9/2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying them. The transport could then invoke a read callback that had been… | |
| Aplazada | Media (5.3) | 0.25% | — | Facebook ProxygenAI | 28/9/2026 | 30/9/2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of… | |
| Aplazada | Alta (7.3) | 0.19% | — | Facebook ProxygenAI | 28/9/2026 | 1/10/2026 | In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it. | |
| Aplazada | Alta (8.8) | 0.31% | — | Mediaflow ProxyAI | 25/9/2026 | 30/9/2026 | MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the… | |
| Aplazada | Crítica (9.3) | 0.25% | — | S2s-proxyAI | 23/9/2026 | 24/9/2026 | All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use Go's RequireAnyClientCert mode when skipCAVerification is false. This mode checks that the client holds the certificate's private key but does not verify the certificate against the configured CA. An… | |
| En análisis | Alta (7.5) | 0.52% | — | Envoyproxy EnvoyAI | 21/9/2026 | 23/9/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's router strips the semicolon suffix before matching but the RBAC url_path matcher evaluates the raw path. A downstream… | |
| En análisis | Media (5.3) | 0.55% | — | Envoyproxy EnvoyAIApache TomcatAI | 21/9/2026 | 23/9/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache Tomcat strip semicolon matrix parameters from each path segment before resolving the resource. Envoy's… | |
| En análisis | Alta (7.4) | 0.60% | — | Envoyproxy EnvoyAI | 21/9/2026 | 23/9/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. A data-plane component such as… | |
| Aplazada | Media (5.5) | 0.45% | — | Nginxproxymanager Nginx Proxy ManagerAI | 20/9/2026 | 22/9/2026 | A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is… | |
| Pendiente de análisis | Baja (3.2) | 0.14% | — | Freedesktop Xdg-dbus-proxyAI | 18/9/2026 | 22/9/2026 | xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Caddy Proxy ManagerAI | 17/9/2026 | 23/9/2026 | Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration by default at /api/auth/sign-up/email, allowing an unauthenticated remote actor to create an active account with the user role without… | |
| Pendiente de análisis | Crítica (9.1) | 0.33% | — | Fastify Proxy-addrAI | 16/9/2026 | 17/9/2026 | @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the… | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (8.2) | 0.28% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (7.1) | 0.25% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication… | |
| Pendiente de análisis | Alta (7.5) | 0.16% | — | IBM Security Verify Identity Access Reverse ProxyAI | 15/9/2026 | 16/9/2026 | IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Aplazada | Alta (7.5) | 0.72% | — | Vouch ProxyAI | 15/9/2026 | 30/9/2026 | Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the value to make([]string, numParts) without checking that the value is positive or… | |
| Pendiente de análisis | Crítica (9.1) | 0.33% | — | Nodejs Proxy-addrAI | 15/9/2026 | 16/9/2026 | proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct… | |
| Pendiente de análisis | Media (5.4) | 0.31% | — | IBM Sterling Secure ProxyAI | 14/9/2026 | 16/9/2026 | IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup. | |
| Pendiente de análisis | Media (4.3) | 0.36% | — | IBM Sterling Secure ProxyAI | 14/9/2026 | 16/9/2026 | IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass. | |
| Aplazada | Media (6.9) | 0.47% | — | GoproxyAI | 14/9/2026 | 23/9/2026 | goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic… |