Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
400.517 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.… | |
| Pendiente de análisis | Crítica (9.8) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Pendiente de análisis | Alta (7.5) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Pendiente de análisis | Media (5.3) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server:… | |
| Pendiente de análisis | Crítica (9.8) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Pendiente de análisis | Alta (7.5) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Pendiente de análisis | Crítica (9.8) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Pendiente de análisis | Alta (7.5) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Pendiente de análisis | Alta (7.5) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck… | |
| Recibida | Baja (3.7) | — | — | HCL AionAI | 1/10/2026 | 1/10/2026 | HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks such as Cross-Site Scripting (XSS) by restricting the sources from which scripts, styles, and other resources can be loaded. The absence of this header may reduce the… | |
| Pendiente de análisis | Alta (8.1) | — | — | — | 1/10/2026 | 1/10/2026 | The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation. | |
| Recibida | Crítica (9.3) | — | — | Watchguard Kernel Memory Access DriverAI | 1/10/2026 | 1/10/2026 | A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process… | |
| Pendiente de análisis | Alta (7.7) | — | — | Theforeman ForemanAI | 1/10/2026 | 1/10/2026 | A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection… | |
| Pendiente de análisis | Alta (8.2) | — | — | Theforeman ForemanAI | 1/10/2026 | 1/10/2026 | A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call… | |
| Pendiente de análisis | Alta (8.2) | — | — | Theforeman ForemanAI | 1/10/2026 | 1/10/2026 | A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo… | |
| Pendiente de análisis | Alta (7.5) | — | — | Redhat ForemanAIRedhat SatelliteAI | 1/10/2026 | 1/10/2026 | A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a… | |
| Pendiente de análisis | Alta (8.8) | — | — | Foreman Remote ExecutionAI | 1/10/2026 | 1/10/2026 | A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the… | |
| Recibida | Alta (7.4) | — | — | Graphql ToolsAI | 1/10/2026 | 1/10/2026 | GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with… | |
| Recibida | Media (5.1) | — | — | Codexonics Prime MoverAI | 1/10/2026 | 1/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory… | |
| Recibida | Alta (7) | — | — | Codexonics Prime MoverAI | 1/10/2026 | 1/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation… | |
| Recibida | Alta (8.6) | — | — | Codexonics Prime MoverAI | 1/10/2026 | 1/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by… | |
| Pendiente de análisis | Media (4.3) | — | — | HCL Bigfix Service ManagementAI | 1/10/2026 | 1/10/2026 | HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing systems. | |
| Pendiente de análisis | Media (4.8) | — | — | Fortra Boks Server AgentAI | 1/10/2026 | 1/10/2026 | Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can… | |
| Recibida | Crítica (9.4) | — | — | Classroom50AI | 1/10/2026 | 1/10/2026 | Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each student's assignment repository and then writes autograde artifacts (`result.json` and `results.json`) into the just-cloned working tree. The write… | |
| Pendiente de análisis | Alta (7.5) | — | — | Fortra Boks ManagerAI | 1/10/2026 | 1/10/2026 | Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service… |