Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3709 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.15%—Oracle Communications Pricing Design Center21/7/202631/7/2026
Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the…
AnalizadaMedia (6.1)0.24%—Oracle Commerce Service Center21/7/20267/8/2026
Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center. Successful…
AnalizadaAlta (8.7)2.2%—Tenable Security Center21/7/202618/8/2026
The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.
AnalizadaAlta (7.1)0.32%—Tenable Security Center21/7/202618/8/2026
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.
AnalizadaCrítica (9.4)2.3%—Tenable Security Center21/7/202618/8/2026
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.
AnalizadaCrítica (9.4)0.80%—Tenable Security Center21/7/202618/8/2026
Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.
AnalizadaCrítica (9.4)0.32%—Tenable Security Center21/7/202618/8/2026
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
AnalizadaAlta (8.2)0.44%—Atlassian Confluence Data Center21/7/202611/8/2026
This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an unauthenticated attacker to view sensitive…
AnalizadaAlta (7.1)0.43%—Atlassian Confluence Data Center21/7/202610/8/2026
This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable…
AnalizadaAlta (7.5)0.66%—Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center17/7/202622/7/2026
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.1)0.41%—Microsoft Windows Admin Center16/7/202614/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7)0.10%—Remote Control FOR Zoom Contact CenterZoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure16/7/202617/8/2026
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
Pendiente de análisisAlta (8.8)1.2%—Lenovo Xclarity Integrator FOR Windows Admin CenterAI16/7/202616/7/2026
The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.
AnalizadaAlta (8.8)0.99%—Microsoft Windows Admin Center14/7/202624/7/2026
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)1.0%—Microsoft Windows Admin Center14/7/202624/7/2026
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.30%—Microsoft Windows Admin Center14/7/202617/7/2026
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
AnalizadaAlta (7.8)0.30%—Microsoft Windows Admin Center14/7/202621/7/2026
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.5)0.84%—Microsoft Windows Admin Center14/7/202621/7/2026
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.75%—Microsoft Windows Admin Center14/7/202621/7/2026
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
AplazadaCrítica (10)0.50%—Siemens Opcenter XAI14/7/202615/7/2026
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user…
AplazadaAlta (8.5)0.16%—Siemens ComosAISiemens Designcenter NXAISiemens Simcenter 3DAISiemens Simcenter FemapAI+614/7/20265/10/2026
A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter…
AplazadaAlta (8.5)0.16%—Gigabyte Control CenterAIGigabyte Mbstorage DramAI13/7/202614/7/2026
The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the module, thereby arbitrarily reading and…
AplazadaAlta (7.5)0.27%💥 PoCKyocera Command Center RXAIKyocera Taskalfa 2552ciAIKyocera Taskalfa 3252ciAIKyocera Taskalfa 2553ciAI+129/7/202610/7/2026
Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive information can be obtained. This affects…
Pendiente de análisisAlta (7.5)0.50%—Genetec Security CenterAI6/7/20267/7/2026
A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unauthenticated attacker to access live video streams.
AnalizadaAlta (7.5)0.65%—Cisco Catalyst CenterCisco Catalyst Center Global Manager1/7/202617/9/2026
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.
Orbitaley — Vulnerabilidades