Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (3.3) | 0.10% | — | HCL DfmproAIHCL DfxanalyticsAIHCL DfxserverAI | 17/7/2026 | 29/9/2026 | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary. | |
| Analizada | Crítica (9.8) | 2.8% | — | Linuxserver Docker-heimdall | 30/7/2025 | 17/6/2026 | LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external… | |
| Analizada | Media (6.1) | 0.56% | — | Linuxserver Heimdall Application Dashboard | 27/7/2025 | 17/6/2026 | LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter. | |
| Aplazada | Media (4.3) | 0.34% | — | GomatrixserverlibAI | 16/1/2025 | 17/6/2026 | Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advised to upgrade. Users unable to upgrade should use a local… | |
| Aplazada | Crítica (9.1) | 2.5% | — | CFX FxserverAI | 13/1/2025 | 5/7/2026 | Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint | |
| Aplazada | Media (5.3) | 0.39% | — | Xserver Typesquare WebfontsAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in XSERVER Inc. TypeSquare Webfonts allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects TypeSquare Webfonts: from n/a through 2.0.7. | |
| Aplazada | Crítica (9.6) | 0.26% | — | Xserver MigratorAI | 2/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary File Upload in Xserver Migrator.This issue affects Xserver Migrator: from n/a through 1.6.1. | |
| Aplazada | Crítica (9.8) | 0.70% | — | Linuxserver HeimdallAI | 1/4/2024 | 17/6/2026 | LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring. | |
| Modificada | Media (5.4) | 0.40% | — | Linuxserver Heimdall Application Dashboard | 27/12/2022 | 17/6/2026 | Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page. | |
| Modificada | Alta (8.8) | 0.82% | — | Matrix DendriteGomatrixserverlib | 19/8/2022 | 17/6/2026 | gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power level parsing within gomatrixserverlib was failing to parse the `"events_default"` key of the `m.room.power_levels` event, defaulting the event default power level to… | |
| Modificada | Alta (8.8) | 2.6% | — | Smartfoxserver | 9/2/2021 | 17/6/2026 | An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enable the Console module. | |
| Modificada | Media (5.5) | 0.37% | — | Smartfoxserver | 9/2/2021 | 17/6/2026 | An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml. | |
| Modificada | Media (5.4) | 1.3% | — | Smartfoxserver | 9/2/2021 | 17/6/2026 | An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affected site. | |
| Modificada | Baja (2.1) | 0.38% | — | X.org-xserverCanonical Ubuntu Linux | 13/5/2013 | 16/6/2026 | X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty. | |
| Modificada | Baja (3.6) | 0.34% | — | X.org-xserver | 5/9/2012 | 16/6/2026 | The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw." | |
| Modificada | Alta (7.5) | 5.1% | — | SUN Solaris LibfontSUN Solaris LibxfontX.org Xserver | 18/1/2008 | 16/6/2026 | Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table. | |
| Modificada | Alta (9.3) | 2.5% | — | X.org EVIX.org Mit-shmX.org Xserver | 18/1/2008 | 16/6/2026 | Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to… | |
| Modificada | Media (5) | 5.3% | — | X.org Xserver | 18/1/2008 | 16/6/2026 | X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists. | |
| Modificada | Alta (9.3) | 3.3% | — | X.org XserverXfree86 Project Xfree86-misc | 18/1/2008 | 16/6/2026 | Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a PassMessage request containing a large array index. | |
| Modificada | Media (5) | 1.7% | — | X.org Tog-cupX.org Xserver | 18/1/2008 | 16/6/2026 | The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index. | |
| Modificada | Media (5) | 6.8% | — | Nipun Jain Xserver | 24/7/2007 | 16/6/2026 | Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request with a long URI. | |
| Modificada | Media (5.5) | 4.4% | — | X.org X Window SystemX.org Xserver | 2/5/2007 | 16/6/2026 | The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions, which trigger a divide-by-zero error. | |
| Modificada | Alta (7.5) | 1.6% | — | Maxserver Xyplex Terminal Server | 26/11/1997 | 16/6/2026 | Xyplex terminal server 6.0.1S1, and possibly other versions, allows remote attackers to bypass the password prompt by entering (1) a CTRL-Z character, or (2) a ? (question mark). |