Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
8534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.2) | — | — | Cisco FinesseAICisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAICisco Unified Contact Center ExpressAI | 7/10/2026 | 7/10/2026 | A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this… | |
| Pendiente de análisis | Media (4.8) | 0.34% | — | Veeam Backup Enterprise ManagerAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link. | |
| En análisis | Alta (8.7) | 0.41% | — | Github Enterprise ServerAI | 6/10/2026 | 7/10/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed a repository contributor to cause the appliance to issue requests to attacker-controlled internal hosts, which could be chained to achieve remote code execution on the appliance. The secret scanning validator for… | |
| En análisis | Media (6) | 0.45% | — | Github Enterprise ServerAI | 6/10/2026 | 7/10/2026 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository collaborator with write access to delete the current default branch through the GraphQL API and cause an attacker-controlled branch to become the new default. In repositories that required pull-request review but… | |
| Aplazada | Alta (8.1) | 0.17% | — | Logicaldoc EnterpriseAI | 6/10/2026 | 7/10/2026 | LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injection in the WorkflowsDataServlet component, allowing authenticated user to manipulate SQL queries via crafted workflow template name. | |
| Aplazada | Media (5.5) | 0.25% | — | Risesoft Y9 Workflow EngineAI | 29/9/2026 | 30/9/2026 | A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. Performing a manipulation of the argument year/processInstanceId results in sql injection. Remote exploitation of… | |
| Pendiente de análisis | Alta (8.6) | 0.43% | — | IBM Enterprise Build OF QuarkusAI | 24/9/2026 | 24/9/2026 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Analizada | Crítica (9.3) | 0.68% | — | Github Enterprise Server | 22/9/2026 | 2/10/2026 | A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same… | |
| Analizada | Alta (7.4) | 0.21% | — | Github Enterprise Server | 22/9/2026 | 2/10/2026 | A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrote quote characters in already-sanitized HTML without re-sanitizing the result.… | |
| Analizada | Media (6) | 0.29% | — | Github Enterprise Server | 22/9/2026 | 2/10/2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tokens for raw pull request diffs and patches were scoped to the repository name and… | |
| Analizada | Media (5.4) | 0.21% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/9/2026 | 7/10/2026 | A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache an allow decision, permitting continued… | |
| Aplazada | Alta (8.8) | 1.8% | — | Tuleap Enterprise EditionAI | 21/9/2026 | 21/9/2026 | An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server. | |
| Pendiente de análisis | Alta (8.8) | 0.69% | — | Grafana OSSAIGrafana EnterpriseAI | 17/9/2026 | 19/9/2026 | Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped… | |
| Pendiente de análisis | Crítica (10) | 0.56% | — | Altium Enterprise ServerAI | 16/9/2026 | 18/9/2026 | A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services that are reachable only from the server… | |
| Aplazada | Alta (7.6) | 0.39% | — | FileriseAI | 16/9/2026 | 16/9/2026 | FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interface and the web application session context. Attackers can combine valid Basic-Auth… | |
| Pendiente de análisis | Alta (7.7) | 0.67% | — | Kong API Gateway EnterpriseAI | 16/9/2026 | 18/9/2026 | A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing algorithm is compatible with the type of key used for verification. As a result, an… | |
| Pendiente de análisis | Alta (7) | 0.28% | — | Oracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAIOracle GraalvmAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM Enterprise Edition: 21.3.19.1; Oracle… | |
| Pendiente de análisis | Alta (7.7) | 0.30% | — | Oracle Peoplesoft Enterprise PeopletoolsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | Oracle Peoplesoft Enterprise FIN Engineering BrazilAI | 15/9/2026 | 17/9/2026 | Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Engineering Brazil… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle Enterprise Manager FOR Fusion MiddlewareAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business… | |
| Aplazada | Alta (7.2) | 0.46% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (7.5) | 0.11% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence… | |
| Aplazada | Alta (7.2) | 0.46% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… |