Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.8) | 0.47% | — | Mitre SAF HeimdallAITenableAI | 29/8/2026 | 1/9/2026 | In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts. | |
| Aplazada | Alta (7.2) | 1.3% | — | Heimdall Data Database ProxyAI | 20/8/2026 | 1/9/2026 | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within the… | |
| Pendiente de análisis | Alta (7.2) | 1.1% | — | Heimdall Data Database ProxyAI | 29/7/2026 | 30/7/2026 | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within… | |
| Aplazada | Alta (7.8) | 0.54% | — | Dadrus HeimdallAI | 8/5/2026 | 17/6/2026 | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request path, while downstream components may normalize dot-segments according to RFC 3986, Section 6.2.2.3. This discrepancy can result in heimdall… | |
| Aplazada | Alta (7.8) | 0.52% | — | Dadrus HeimdallAI | 8/5/2026 | 17/6/2026 | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs host matching in a case-sensitive manner, while HTTP hostnames are case-insensitive. This discrepancy can result in heimdall failing to match a rule for a request host that differs only in… | |
| Aplazada | Alta (7.8) | 0.55% | — | Dadrus HeimdallAI | 8/5/2026 | 17/6/2026 | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-sensitive manner, while percent-encoding is defined to be case-insensitive. As a result, the lowercase equivalent (%2f) is not recognized and therefore not… | |
| Analizada | Alta (7.5) | 0.42% | — | Dadrus Heimdall | 20/3/2026 | 17/6/2026 | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. When using Heimdall in envoy gRPC decision API mode with versions 0.7.0-alpha through 0.17.10, wrong encoding of the query URL string allows rules with non-wildcard path expressions to be bypassed. Envoy splits the requested URL into… | |
| Aplazada | Alta (8.8) | 0.45% | — | Heimdall Data Database ProxyAI | 6/11/2025 | 17/6/2026 | Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Crítica (9.8) | 2.8% | — | Linuxserver Docker-heimdall | 30/7/2025 | 17/6/2026 | LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external… | |
| Analizada | Media (6.1) | 0.56% | — | Linuxserver Heimdall Application Dashboard | 27/7/2025 | 17/6/2026 | LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter. | |
| Aplazada | Crítica (9.8) | 0.70% | — | Linuxserver HeimdallAI | 1/4/2024 | 17/6/2026 | LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring. | |
| Modificada | Media (5.4) | 0.40% | — | Linuxserver Heimdall Application Dashboard | 27/12/2022 | 17/6/2026 | Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page. |