Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3038▲ 464 respecto a la semana anterior
Críticas / altas1416▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)387▲ 170 respecto a la semana anterior
3142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 1.1% | — | MCP Context ForgeAIContext Forge Python Sandbox ServerAI | 15/9/2026 | 30/9/2026 | MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required _getattr_ guard, and relies on… | |
| Analizada | Alta (8.2) | 0.42% | — | Hcltech DFX Server | 16/7/2026 | 21/7/2026 | HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without… | |
| Analizada | Media (6.3) | 0.30% | — | Hcltech DFX Server | 16/7/2026 | 21/7/2026 | HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or… | |
| Analizada | Alta (8.2) | 0.43% | — | Hcltech DFX Server | 16/7/2026 | 21/7/2026 | HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials. | |
| Analizada | Media (6.3) | 0.19% | — | Hcltech DFX Server | 16/7/2026 | 21/7/2026 | HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application. | |
| Aplazada | Crítica (9.1) | 0.55% | — | Andreimarcu Linux-serverAI | 14/7/2026 | 15/7/2026 | An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go | |
| Aplazada | Alta (7.5) | 0.31% | — | Andreimarcu Linux-serverAI | 14/7/2026 | 15/7/2026 | Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the uploadPutHandler function | |
| Analizada | Crítica (9) | 0.31% | — | X.org X ServerX.org Xwayland | 8/7/2026 | 9/7/2026 | Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory. | |
| Analizada | Alta (7.8) | 0.33% | — | X.org X ServerX.org Xwayland | 8/7/2026 | 9/7/2026 | Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks. | |
| Aplazada | Alta (7.5) | 0.46% | — | Andreimarcu Linx-serverAI | 15/6/2026 | 17/6/2026 | An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Alta (7.8) | 0.20% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 27/7/2026 | An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the… | |
| Modificada | Media (5.5) | 0.19% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure. | |
| Modificada | Media (5.5) | 0.18% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which… | |
| Modificada | Alta (7.8) | 0.20% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege… | |
| Modificada | Alta (7.8) | 0.20% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if… | |
| Modificada | Alta (7.8) | 0.22% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to… | |
| Modificada | Alta (7.8) | 0.22% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger… | |
| Modificada | Alta (7.8) | 0.20% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence,… | |
| Modificada | Alta (7.8) | 0.21% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is… | |
| Modificada | Alta (7.5) | 1.1% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 18/5/2026 | 29/9/2026 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable… | |
| Modificada | Crítica (9.1) | 0.53% | — | X.org X ServerRedhat Enterprise Linux | 5/5/2026 | 17/6/2026 | A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can… | |
| Modificada | Crítica (9.1) | 0.53% | — | X.org X ServerRedhat Enterprise Linux | 5/5/2026 | 17/6/2026 | A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server, either locally or… | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | X.org X ServerAI | 23/4/2026 | 15/7/2026 | A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of… | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | X.org X ServerAI | 23/4/2026 | 15/7/2026 | A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory… | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | X.org X ServerAI | 23/4/2026 | 15/7/2026 | A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service (DoS) or other… |