Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

8534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.2)——Cisco FinesseAICisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAICisco Unified Contact Center ExpressAI7/10/20267/10/2026
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this…
Pendiente de análisisMedia (4.8)0.34%—Veeam Backup Enterprise ManagerAI7/10/20267/10/2026
This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link.
En análisisAlta (8.7)0.41%—Github Enterprise ServerAI6/10/20267/10/2026
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed a repository contributor to cause the appliance to issue requests to attacker-controlled internal hosts, which could be chained to achieve remote code execution on the appliance. The secret scanning validator for…
En análisisMedia (6)0.45%—Github Enterprise ServerAI6/10/20267/10/2026
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository collaborator with write access to delete the current default branch through the GraphQL API and cause an attacker-controlled branch to become the new default. In repositories that required pull-request review but…
AplazadaAlta (8.1)0.17%—Logicaldoc EnterpriseAI6/10/20267/10/2026
LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injection in the WorkflowsDataServlet component, allowing authenticated user to manipulate SQL queries via crafted workflow template name.
AplazadaMedia (5.5)0.25%—Risesoft Y9 Workflow EngineAI29/9/202630/9/2026
A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. Performing a manipulation of the argument year/processInstanceId results in sql injection. Remote exploitation of…
Pendiente de análisisAlta (8.6)0.43%—IBM Enterprise Build OF QuarkusAI24/9/202624/9/2026
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
AnalizadaCrítica (9.3)0.68%—Github Enterprise Server22/9/20262/10/2026
A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same…
AnalizadaAlta (7.4)0.21%—Github Enterprise Server22/9/20262/10/2026
A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrote quote characters in already-sanitized HTML without re-sanitizing the result.…
AnalizadaMedia (6)0.29%—Github Enterprise Server22/9/20262/10/2026
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tokens for raw pull request diffs and patches were scoped to the repository name and…
AnalizadaMedia (5.4)0.21%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux22/9/20267/10/2026
A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache an allow decision, permitting continued…
AplazadaAlta (8.8)1.8%—Tuleap Enterprise EditionAI21/9/202621/9/2026
An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server.
Pendiente de análisisAlta (8.8)0.69%—Grafana OSSAIGrafana EnterpriseAI17/9/202619/9/2026
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped…
Pendiente de análisisCrítica (10)0.56%—Altium Enterprise ServerAI16/9/202618/9/2026
A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services that are reachable only from the server…
AplazadaAlta (7.6)0.39%—FileriseAI16/9/202616/9/2026
FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interface and the web application session context. Attackers can combine valid Basic-Auth…
Pendiente de análisisAlta (7.7)0.67%—Kong API Gateway EnterpriseAI16/9/202618/9/2026
A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing algorithm is compatible with the type of key used for verification. As a result, an…
Pendiente de análisisAlta (7)0.28%—Oracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAIOracle GraalvmAI15/9/202616/9/2026
Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM Enterprise Edition: 21.3.19.1; Oracle…
Pendiente de análisisAlta (7.7)0.30%—Oracle Peoplesoft Enterprise PeopletoolsAI15/9/202617/9/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While…
Pendiente de análisisAlta (7.8)0.14%—Oracle Peoplesoft Enterprise FIN Engineering BrazilAI15/9/202617/9/2026
Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Engineering Brazil…
Pendiente de análisisCrítica (9.8)0.48%—Oracle Enterprise Manager FOR Fusion MiddlewareAI15/9/202616/9/2026
Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager…
AplazadaAlta (7.8)0.14%—Oracle Business Intelligence Enterprise EditionAI15/9/202617/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business…
AplazadaAlta (8.8)0.42%—Oracle Business Intelligence Enterprise EditionAI15/9/202617/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business…
AplazadaAlta (7.2)0.46%—Oracle Business Intelligence Enterprise EditionAI15/9/202617/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
AplazadaAlta (7.5)0.11%—Oracle Business Intelligence Enterprise EditionAI15/9/202617/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence…
AplazadaAlta (7.2)0.46%—Oracle Business Intelligence Enterprise EditionAI15/9/202617/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…