Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
366 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 1.5% | — | Solarwinds Observability Self-hostedAI | 22/9/2026 | 24/9/2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode. | |
| Pendiente de análisis | Crítica (9.8) | 0.65% | — | Solarwinds Observability Self-hostedAI | 22/9/2026 | 24/9/2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected. | |
| Pendiente de análisis | Media (5.4) | 0.44% | — | Open Cluster Management Multicluster Observability AddonAIOpen Cluster Management Addon FrameworkAI | 18/9/2026 | 21/9/2026 | A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details,… | |
| Pendiente de análisis | Media (5.7) | 0.22% | — | Suse ObservabilityAIRancher-extension-stackstateAI | 17/9/2026 | 29/9/2026 | The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment. | |
| Pendiente de análisis | Alta (7.7) | 0.47% | — | Redhat Multicluster Observability AddonAIRedhat Opentelemetry CollectorAIRedhat Cluster LOG ForwarderAI | 11/9/2026 | 21/9/2026 | A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on… | |
| Pendiente de análisis | Alta (7.7) | 0.31% | — | IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI | 4/9/2026 | 10/9/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an… | |
| Pendiente de análisis | Crítica (9.6) | 0.21% | — | IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI | 4/9/2026 | 8/9/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace… | |
| Pendiente de análisis | Media (6.2) | 0.52% | — | Opensearch Dashboards-observabilityAI | 21/8/2026 | 27/8/2026 | Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web… | |
| Aplazada | Alta (8.7) | 0.51% | — | Stability AI Stable Diffusion WebuiAI | 21/8/2026 | 24/9/2026 | to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment comparison performed by is_path_trusted in scripts/iib/api.py while pointing outside… | |
| Aplazada | Crítica (9.3) | 0.43% | — | PTC Windchill Risk AND ReliabilityAI | 20/8/2026 | 9/9/2026 | A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition. | |
| Analizada | Alta (7.3) | 0.16% | — | Oracle Service Delivery Platform Number Portability | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SDP Number Portability executes… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Service Delivery Platform Number Portability | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SDP Number Portability.… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Hyperion Profitability AND Cost Management | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Hyperion Profitability AND Cost Management | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Hyperion Profitability AND Cost Management | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability… | |
| Analizada | Alta (7.1) | 0.38% | — | Oracle Hyperion Profitability AND Cost Management | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Hyperion Profitability AND Cost Management | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Profitability… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Hyperion Profitability AND Cost Management | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Hyperion Profitability AND Cost Management | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Profitability… | |
| Aplazada | Media (5.1) | 0.39% | — | Vulnerability-lookupAI | 12/8/2026 | 26/8/2026 | Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instance addresses were validated only for basic URL syntax before being stored, while the synchronization worker later dereferenced these addresses using requests.get() with… | |
| Aplazada | Alta (8.8) | 0.35% | — | Vulnerability-lookupAI | 12/8/2026 | 26/8/2026 | Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using stateless signed tokens containing only the user's login. Although the token signature and age were validated, the application did not track whether a… | |
| Aplazada | Media (5.3) | 0.50% | — | Vulnerability-lookupAI | 12/8/2026 | 26/8/2026 | An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/<topic> endpoint. The token_required decorator used by the Pub/Sub interface authenticated requests solely by matching the X-API-KEY… | |
| Aplazada | Media (6.1) | 0.57% | — | Vulnerability-lookupAI | 12/8/2026 | 26/8/2026 | A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter used to display reference tags associated with vulnerability records. Values from containers.cna.references[].tags[] were directly interpolated into HTML badge elements and the resulting string was… | |
| Pendiente de análisis | Media (5.6) | 0.12% | — | Intel Active Management TechnologyAIIntel Standard ManageabilityAI | 11/8/2026 | 12/8/2026 | Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may… | |
| Pendiente de análisis | Alta (8.2) | 0.32% | — | Intel Active Management TechnologyAIIntel Standard ManageabilityAI | 11/8/2026 | 12/8/2026 | Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially… |