Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.25% | — | Proxmox Pmg-apiAI | 21/9/2026 | 24/9/2026 | In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to the underlying apt-get command when fetching package changelogs. It requires authentication but can be exploited in a CSRF-style attack. | |
| Aplazada | Crítica (9.3) | 3.2% | — | Proxmox Virtual EnvironmentAIProxmox Libpve-access-controlAI | 1/9/2026 | 8/9/2026 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login… | |
| Aplazada | Media (6.5) | 0.34% | — | Proxmox Virtual EnvironmentAIProxmox Qemu-serverAI | 17/7/2026 | 17/7/2026 | Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API. | |
| Aplazada | Alta (7.2) | 0.39% | — | Proxmox Virtual EnvironmentAIProxmox Pve-managerAIProxmox Qemu-serverAIProxmox Pve-containerAI | 17/7/2026 | 17/7/2026 | A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call… | |
| Aplazada | Media (6.1) | 0.25% | — | Proxmox Virtual EnvironmentAI | 17/7/2026 | 17/7/2026 | A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. | |
| Analizada | Crítica (9.8) | 0.52% | — | Proxmox Libpve-storage-perl | 17/7/2026 | 11/8/2026 | libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability. | |
| Analizada | Media (5.4) | 0.29% | — | Proxmox Virtual Environment | 9/9/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side… | |
| Analizada | Media (5.4) | 0.29% | — | Proxmox Virtual Environment | 9/9/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated users to store malicious input. The payload is rendered unsafely in the Web UI and executed when viewed by other users, potentially leading to session… | |
| Analizada | Media (5.4) | 0.34% | — | Proxmox Virtual Environment | 9/9/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 allows an authenticated user to inject malicious input. The input is stored and executed in the context of other users' browsers when they view the affected… | |
| Aplazada | Alta (8.2) | 0.36% | — | Proxmox Virtual EnvironmentAI | 25/9/2024 | 17/6/2026 | Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against malicious API response values allow authenticated attackers with 'Sys.Audit' or 'VM.Monitor' privileges to download arbitrary host files via the API. When handling the result from a… | |
| Modificada | Media (6.1) | 0.39% | — | Proxmox-widget-toolkit | 28/10/2023 | 17/6/2026 | Proxmox proxmox-widget-toolkit before 4.0.9, as used in multiple Proxmox products, allows XSS via the edit notes feature. | |
| Modificada | Alta (8.8) | 1.4% | — | Proxmox Backup ServerProxmox Mail GatewayProxmox Virtual Environment | 27/9/2023 | 17/6/2026 | An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component. | |
| Modificada | Crítica (9) | 1.3% | — | Proxmox Virtual Environment | 14/12/2022 | 9/7/2026 | A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/. | |
| Modificada | Crítica (9.8) | 1.2% | — | Proxmox Mail GatewayProxmox PVE Http ServerProxmox Virtual Environment | 4/12/2022 | 17/6/2026 | Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway,… | |
| Modificada | Alta (7.1) | 1.4% | — | Proxmox Mail GatewayProxmox PVE Http ServerProxmox Virtual Environment | 4/12/2022 | 17/6/2026 | A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow… | |
| Modificada | Media (6.5) | 0.82% | — | Jenkins Proxmox | 29/3/2022 | 17/6/2026 | Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified host using attacker-specified username and password (perform a connection test), disable SSL/TLS validation for the entire Jenkins… | |
| Modificada | Media (6.5) | 0.54% | — | Jenkins Proxmox | 29/3/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier allows attackers to connect to an attacker-specified host using attacker-specified username and password (perform a connection test), disable SSL/TLS validation for the entire Jenkins controller JVM as part of the connection… | |
| Modificada | Alta (7.5) | 0.67% | — | Jenkins Proxmox | 29/3/2022 | 17/6/2026 | Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM when configured to ignore SSL/TLS issues. | |
| Modificada | Media (6.5) | 0.92% | — | Jenkins Proxmox | 29/3/2022 | 17/6/2026 | Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Alta (7.8) | 0.27% | — | Theforeman Foremanfogproxmox | 7/6/2021 | 17/6/2026 | A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Versions before… | |
| Modificada | Media (5.3) | 1.2% | — | Proxmox Virtual Environment | 27/1/2020 | 17/6/2026 | Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability | |
| Modificada | Media (6.1) | 0.88% | — | Proxmox Mail Gateway | 3/5/2017 | 17/6/2026 | Open redirect vulnerability in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter. | |
| Modificada | Media (6.1) | 0.77% | — | Proxmox Mail Gateway | 3/5/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allow remote attackers to inject arbitrary web script or HTML via multiple parameters, related to /users/index.htm, /quarantine/spam/manage.htm, /quarantine/spam/whitelist.htm, /queues/mail/index/,… | |
| Modificada | Media (4.3) | 1.2% | — | Proxmox Mail Gateway | 14/3/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway before 3.1-5829 allow remote attackers to inject arbitrary web script or HTML via the (1) state parameter to objects/who/index.htm or (2) User email address to quarantine/spam/manage.htm. |