Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
8466 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.83% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 31/7/2026 | 18/8/2026 | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by… | |
| Modificada | Alta (7.5) | 0.53% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 31/7/2026 | 18/8/2026 | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the… | |
| Pendiente de análisis | Alta (7.5) | 0.55% | — | IBM Enterprise Build OF QuarkusAIQuarkus RestAI | 30/7/2026 | 30/7/2026 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes. | |
| Analizada | Crítica (9.8) | 0.73% | — | IBM APP Connect Enterprise | 30/7/2026 | 5/8/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system. | |
| Analizada | Crítica (9.8) | 1.0% | — | IBM APP Connect Enterprise | 30/7/2026 | 5/8/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters. | |
| Analizada | Alta (7.5) | 0.62% | — | IBM APP Connect Enterprise | 30/7/2026 | 5/8/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability. | |
| Analizada | Alta (7.5) | 0.40% | — | IBM APP Connect Enterprise | 30/7/2026 | 5/8/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user. | |
| Analizada | Alta (7.7) | 0.51% | — | Enterprisedb Pglogical | 28/7/2026 | 24/8/2026 | A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has been freed or recycled during normal worker lifecycle events. The condition is reachable during normal replication operation, including by a low-privileged user able to… | |
| Analizada | Crítica (9) | 0.40% | — | Enterprisedb Pglogical | 28/7/2026 | 24/8/2026 | When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber. Because the apply worker runs at a privilege level equivalent to a PostgreSQL superuser in default installations, any function invoked by such a default… | |
| Analizada | Crítica (9) | 0.41% | — | Enterprisedb Pglogical | 28/7/2026 | 24/8/2026 | The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a PostgreSQL superuser in default installations. A party acting as the publisher can… | |
| Analizada | Media (6.1) | 0.38% | — | Enterprisedb Pglogical | 28/7/2026 | 24/8/2026 | pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copying them, resulting in an out-of-bounds read. A party acting as the publisher for a subscription, for example a non-PostgreSQL endpoint that speaks the pglogical replication… | |
| Aplazada | Alta (8.7) | 0.44% | — | Anchore EnterpriseAI | 28/7/2026 | 28/7/2026 | Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources… | |
| Analizada | Alta (7.1) | 0.30% | — | GimpRedhat Enterprise Linux | 27/7/2026 | 24/8/2026 | A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues… | |
| Analizada | Media (5.5) | 0.23% | — | GimpRedhat Enterprise Linux | 27/7/2026 | 10/8/2026 | A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize… | |
| Modificada | Alta (7.8) | 0.30% | — | GimpRedhat Enterprise Linux | 27/7/2026 | 30/9/2026 | A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based… | |
| Analizada | Media (6.5) | 0.25% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information… | |
| Analizada | Alta (7.2) | 0.28% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing… | |
| Analizada | Media (6.5) | 0.38% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or… | |
| Aplazada | Media (5.2) | 0.24% | — | Tridium Niagara FrameworkAITridium Niagara Enterprise SecurityAI | 23/7/2026 | 23/7/2026 | Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Peoplesoft Enterprise FIN Manufacturing Brazil | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise FIN Manufacturing… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Peoplesoft Enterprise FIN Manufacturing Argentina | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects… | |
| Analizada | Alta (8.2) | 0.32% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware… | |
| Analizada | Crítica (9.9) | 0.37% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common… |