Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3021▲ 414 respecto a la semana anterior
Críticas / altas1420▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 169 respecto a la semana anterior
25.695 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.9) | — | — | Amazon Security Agent MCP ServerAI | 1/10/2026 | 1/10/2026 | An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan… | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces. | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.… | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry… | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68. | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version… | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname… | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.… | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server:… | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Recibida | Sin puntuar | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck… | |
| Recibida | Media (4.8) | — | — | Fortra Boks Server AgentAI | 1/10/2026 | 1/10/2026 | Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can… | |
| Recibida | Alta (7.5) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Recibida | Alta (7.5) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Recibida | Baja (3.7) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server:… | |
| Pendiente de análisis | Alta (7.1) | — | — | Octopus ServerAI | 1/10/2026 | 1/10/2026 | In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization. | |
| Aplazada | Crítica (9.3) | — | — | Genian NAC Ztna Policy ServerAI | 1/10/2026 | 1/10/2026 | Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions | |
| Pendiente de análisis | Crítica (9.4) | 0.40% | — | Litespeed WEB ServerAI | 30/9/2026 | 30/9/2026 | LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case." | |
| Aplazada | Media (6.5) | 0.22% | — | Dash10 Oauth ServerAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. |