Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2561▼ 316 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.16%—IBM Security Verify Identity Access Reverse ProxyAI15/9/202616/9/2026
IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
AnalizadaMedia (5.3)0.30%—Reverse Proxy Header Project Reverse Proxy Header30/10/202517/6/2026
Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables.This issue affects Reverse Proxy Header: from 0.0.0 before 1.1.2.
ModificadaAlta (7.5)2.2%—Microsoft YET Another Reverse Proxy23/6/202317/6/2026
Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability
ModificadaAlta (8.8)0.45%—Jenkins Reverse Proxy Auth16/5/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials.
ModificadaMedia (6.5)0.69%—Jenkins Reverse Proxy Auth15/11/202217/6/2026
Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
ModificadaAlta (7.5)3.5%—Microsoft YET Another Reverse Proxy15/4/202217/6/2026
YARP Denial of Service Vulnerability
ModificadaCrítica (9.8)1.4%—Pexip InfinityPexip Reverse Proxy AND Turn Server25/9/202017/6/2026
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.
ModificadaBaja (3.3)0.34%—Jenkins Reverse Proxy Auth5/4/201817/6/2026
An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users.
ModificadaMedia (5)2.5%—At32 Reverse Proxy8/10/201216/6/2026
at32 Reverse Proxy 1.060.310 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long string in an HTTP header field, as demonstrated using the If-Unmodified-Since field.