Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
3817 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.41% | — | Zhilink ADP Application Developer PlatformAI | 21/6/2026 | 22/6/2026 | A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part of the component testConnection Endpoint. The manipulation of the argument jdbcUrl results in deserialization. The attack may be performed from remote. The exploit has been made public and… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Applications Manager | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Manager. While… | |
| Analizada | Crítica (9.1) | 0.45% | 💥 PoC | Oracle Application Performance Management | 17/6/2026 | 18/6/2026 | Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise APM - Application… | |
| Analizada | Media (4.7) | 0.14% | — | Oracle Application Development Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle… | |
| Analizada | Media (4.1) | 0.14% | — | Oracle Application Development Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Application Development Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Application Development Framework | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise… | |
| Aplazada | Crítica (9.3) | 0.35% | — | Yarbo Android ApplicationAIYarbo IOS ApplicationAI | 12/6/2026 | 17/6/2026 | The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carrying real-time… | |
| Aplazada | Media (4.3) | 1.0% | 💥 Exploit | Spaceapplications YamcsAI | 10/6/2026 | 21/7/2026 | Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13.0 and 5.12.7 patch… | |
| Pendiente de análisis | Media (5.1) | 0.29% | — | Lenovo Android ApplicationAI | 10/6/2026 | 17/6/2026 | A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the built-in browser to overwrite system clipboard contents. | |
| Analizada | Alta (8.1) | 0.65% | — | Vmware Spring FOR Apache KafkaRedhat FuseRedhat Jboss Enterprise Application Platform Expansion Pack | 10/6/2026 | 5/8/2026 | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that… | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | SAP Application Server AbapAI | 9/6/2026 | 23/7/2026 | Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker to execute a report generation command which could overwrite information belonging to another user, resulting in escalation of privileges. This has high impact on integrity with low impact on… | |
| Pendiente de análisis | Crítica (9.9) | 0.32% | — | SAP Netweaver Application Server AbapAISAP Abap PlatformAI | 9/6/2026 | 23/7/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data… | |
| Pendiente de análisis | Crítica (9) | 0.63% | — | SAP Netweaver Application Server JavaAI | 9/6/2026 | 23/7/2026 | SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive… | |
| Analizada | Media (6.9) | 0.46% | — | KJD Internationalized Domain Names IN Applications | 5/6/2026 | 23/7/2026 | Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `"\u0660" * N` or `"\u30fb" * N + "\u6f22"` utilize the `valid_contexto` function prior to… | |
| Analizada | Crítica (9.8) | 77% | ⚠ Explotación activa💥 Exploit | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 4/6/2026 | 1/10/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints | |
| Analizada | Alta (8.5) | 0.68% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain. | |
| Analizada | Crítica (9) | 0.62% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security. | |
| Analizada | Crítica (9) | 0.64% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. | |
| Analizada | Crítica (9.1) | 0.47% | — | IBM Websphere Application Server | 1/6/2026 | 22/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. | |
| Aplazada | Alta (8.8) | 0.43% | — | Frontier X Mobile ApplicationAISeil X2AI | 29/5/2026 | 22/7/2026 | The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations,… | |
| Pendiente de análisis | Baja (2) | 0.13% | — | Strongdm Desktop ApplicationAIStrongdm Desktop ClientAIMicrosoft WindowsAI | 29/5/2026 | 6/10/2026 | StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS… | |
| Modificada | Media (5.9) | 0.30% | — | IBM Websphere Application Server | 27/5/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window. | |
| Analizada | Alta (7.5) | 0.69% | — | IBM Websphere Application Server | 27/5/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to… | |
| Analizada | Media (6.5) | 0.42% | — | IBM Cloud Application Performance Managemen | 27/5/2026 | 17/6/2026 | IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced environment. |