Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
4639 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (3.5) | — | — | HCL Bigfix Service ManagementAI | 6/10/2026 | 6/10/2026 | HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to supply unexpected or malformed data, enabling processing errors, business logic bypasses, and unintended application behavior. | |
| Pendiente de análisis | Crítica (9.3) | 0.74% | 💥 Exploit | Atlassian Bitbucket Data CenterAIAtlassian Confluence Data CenterAIAtlassian Jira Service Management Data CenterAIAtlassian Jira Software Data CenterAI+4 | 5/10/2026 | 6/10/2026 | This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web… | |
| Aplazada | Crítica (9.8) | 0.29% | — | Dormakaba Evolo ServiceAI | 5/10/2026 | 6/10/2026 | An issue in dormakaba evolo Service (all versions) allows a remote attacker to execute arbitrary code as SYSTEM via a .NET component. | |
| Aplazada | Crítica (9.1) | 0.88% | — | Vikappointments Services Booking CalendarAI | 3/10/2026 | 6/10/2026 | The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which… | |
| Aplazada | Alta (7.1) | 0.18% | — | GG Soft Software Services PaperworkAI | 2/10/2026 | 2/10/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection. This issue affects Paperwork: through 2026-09-09. | |
| Aplazada | Alta (7.2) | 0.49% | — | Document Merge ServiceAI | 1/10/2026 | 2/10/2026 | Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as… | |
| Analizada | Baja (3.7) | 0.21% | — | Hcltech Bigfix Service Management | 1/10/2026 | 6/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks. | |
| Analizada | Media (5.3) | 0.24% | — | Hcltech Bigfix Service Management | 1/10/2026 | 6/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks. | |
| En análisis | Media (4.3) | 0.16% | — | HCL Bigfix Service ManagementAI | 1/10/2026 | 1/10/2026 | HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing systems. | |
| Analizada | Media (5.3) | 0.24% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks. | |
| Analizada | Alta (7.4) | 0.15% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks. | |
| Analizada | Media (5.3) | 0.24% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the discovery of hidden administrative API endpoints for further targeted exploitation. | |
| Analizada | Baja (2.2) | 0.06% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabling Cross-Site Request Forgery (CSRF), session hijacking via Cross-Site Scripting… | |
| Analizada | Alta (7.2) | 0.20% | — | Hcltech Bigfix Service Management | 1/10/2026 | 5/10/2026 | HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling session hijacking and the theft of sensitive data. | |
| Pendiente de análisis | Media (5.7) | 0.11% | — | Canonical WSL PRO ServiceAI | 29/9/2026 | 30/9/2026 | In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding… | |
| Aplazada | Alta (8.8) | 0.24% | 💥 PoC | Iron Mountain Archiving Services EnvisionAI | 28/9/2026 | 28/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655. | |
| Aplazada | Baja (2.1) | 0.27% | — | Acrel Electric Unet WEB ServiceAI | 28/9/2026 | 28/9/2026 | A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has… | |
| Pendiente de análisis | Crítica (9.3) | 0.30% | — | Servicenow AI PlatformAI | 24/9/2026 | 25/9/2026 | ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security… | |
| Pendiente de análisis | Alta (8.7) | 0.29% | — | Servicenow AI PlatformAI | 24/9/2026 | 24/9/2026 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling… | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Servicenow AI PlatformAI | 24/9/2026 | 24/9/2026 | ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete instance data beyond what was intended. In August 2026, ServiceNow deployed a security… | |
| Pendiente de análisis | Alta (8.4) | 0.24% | — | Servicenow AI PlatformAI | 24/9/2026 | 25/9/2026 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling… | |
| Pendiente de análisis | Crítica (9.3) | 0.27% | — | Servicenow AI PlatformAI | 24/9/2026 | 24/9/2026 | ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data… | |
| Aplazada | Media (6.5) | 0.21% | — | Global IT Informatics Technology Services INC WeollAI | 23/9/2026 | 23/9/2026 | Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery. This issue affects Weoll: before 3.2.45.44. | |
| Pendiente de análisis | Alta (8.6) | 1.7% | — | Zohocorp Manageengine Adselfservice PlusAI | 22/9/2026 | 22/9/2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API. | |
| Pendiente de análisis | Crítica (9.8) | 4.6% | — | Zohocorp Manageengine Adselfservice PlusAI | 22/9/2026 | 23/9/2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client. |