Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.6) | — | — | Progress Software Autonomous Rest Connector Genai AgentsAI | 6/10/2026 | 6/10/2026 | An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user… | |
| Aplazada | Alta (8.8) | 0.34% | — | Emilia Progress PlannerAI | 6/10/2026 | 6/10/2026 | Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | ProgressifyAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Progressify - Progressive Web App (PWA) <= 1.6.0 versions. | |
| Pendiente de análisis | Alta (8.8) | 0.26% | — | Progress Sitefinity Nextjs SDKAI | 5/10/2026 | 6/10/2026 | CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information. | |
| Pendiente de análisis | Alta (7.9) | 0.06% | — | Progress Telerik Fiddler ClassicAI | 5/10/2026 | 6/10/2026 | In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a valid Authenticode signature whose… | |
| Pendiente de análisis | Media (6.6) | 0.06% | — | Progress Fiddler ClassicAI | 5/10/2026 | 6/10/2026 | In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Fiddler writes the certificate to a temporary file in a… | |
| Pendiente de análisis | Baja (3.6) | 0.09% | — | Progress Telerik Fiddler ClassicAI | 5/10/2026 | 6/10/2026 | In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames… | |
| Pendiente de análisis | Media (6.3) | 0.09% | — | Progress Fiddler ClassicAI | 5/10/2026 | 6/10/2026 | In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Content-Length headers with conflicting values are forwarded verbatim to the origin server, while Fiddler frames the request… | |
| Pendiente de análisis | Alta (7.7) | 0.09% | — | Progress Software Fiddler EverywhereAI | 29/9/2026 | 30/9/2026 | Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel. | |
| Pendiente de análisis | Media (5.6) | 0.12% | — | Progress Telerik Fiddler EverywhereAI | 29/9/2026 | 30/9/2026 | Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful… | |
| Aplazada | Media (4.3) | 0.16% | — | Ninja Forms Save ProgressAI | 5/9/2026 | 8/9/2026 | The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Pendiente de análisis | Alta (8.1) | 0.16% | — | Progress Telerik UI FOR AjaxAIProgress RadaditorAI | 2/9/2026 | 8/9/2026 | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into,… | |
| Pendiente de análisis | Alta (7.5) | 0.36% | — | Progress Telerik UI FOR AjaxAI | 2/9/2026 | 8/9/2026 | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories. | |
| Analizada | Alta (7.2) | 0.94% | — | Progress Sharefile Storage Zones Controller | 17/8/2026 | 2/9/2026 | In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5… | |
| Analizada | Alta (8) | 0.83% | — | Progress Sharefile Storage Zones Controller | 17/8/2026 | 2/9/2026 | In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host. | |
| Analizada | Alta (7.2) | 0.74% | — | Progress Sharefile Storage Zones Controller | 17/8/2026 | 2/9/2026 | In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of… | |
| Analizada | Alta (8.8) | 0.68% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account. | |
| Analizada | Media (6.8) | 0.35% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. | |
| Analizada | Media (6.8) | 0.38% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root. | |
| Analizada | Media (4.3) | 0.25% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions. | |
| Analizada | Alta (8) | 0.41% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content. | |
| Analizada | Alta (8.5) | 0.34% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the… | |
| Analizada | Crítica (9.3) | 0.65% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions… | |
| Analizada | Crítica (9.9) | 0.46% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database. | |
| Analizada | Crítica (9.8) | 0.83% | — | Progress Marklogic Server | 5/8/2026 | 3/9/2026 | An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators. |