Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3709 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.15% | — | Oracle Communications Pricing Design Center | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Commerce Service Center | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center. Successful… | |
| Analizada | Alta (8.7) | 2.2% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability. | |
| Analizada | Alta (7.1) | 0.32% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access. | |
| Analizada | Crítica (9.4) | 2.3% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality. | |
| Analizada | Crítica (9.4) | 0.80% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint. | |
| Analizada | Crítica (9.4) | 0.32% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database. | |
| Analizada | Alta (8.2) | 0.44% | — | Atlassian Confluence Data Center | 21/7/2026 | 11/8/2026 | This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an unauthenticated attacker to view sensitive… | |
| Analizada | Alta (7.1) | 0.43% | — | Atlassian Confluence Data Center | 21/7/2026 | 10/8/2026 | This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable… | |
| Analizada | Alta (7.5) | 0.66% | — | Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center | 17/7/2026 | 22/7/2026 | Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Windows Admin Center | 16/7/2026 | 14/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7) | 0.10% | — | Remote Control FOR Zoom Contact CenterZoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 16/7/2026 | 17/8/2026 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges. | |
| Pendiente de análisis | Alta (8.8) | 1.2% | — | Lenovo Xclarity Integrator FOR Windows Admin CenterAI | 16/7/2026 | 16/7/2026 | The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands. | |
| Analizada | Alta (8.8) | 0.99% | — | Microsoft Windows Admin Center | 14/7/2026 | 24/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Windows Admin Center | 14/7/2026 | 24/7/2026 | Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Windows Admin Center | 14/7/2026 | 17/7/2026 | Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Windows Admin Center | 14/7/2026 | 21/7/2026 | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.84% | — | Microsoft Windows Admin Center | 14/7/2026 | 21/7/2026 | Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.75% | — | Microsoft Windows Admin Center | 14/7/2026 | 21/7/2026 | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Crítica (10) | 0.50% | — | Siemens Opcenter XAI | 14/7/2026 | 15/7/2026 | A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user… | |
| Aplazada | Alta (8.5) | 0.16% | — | Siemens ComosAISiemens Designcenter NXAISiemens Simcenter 3DAISiemens Simcenter FemapAI+6 | 14/7/2026 | 5/10/2026 | A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter… | |
| Aplazada | Alta (8.5) | 0.16% | — | Gigabyte Control CenterAIGigabyte Mbstorage DramAI | 13/7/2026 | 14/7/2026 | The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the module, thereby arbitrarily reading and… | |
| Aplazada | Alta (7.5) | 0.27% | 💥 PoC | Kyocera Command Center RXAIKyocera Taskalfa 2552ciAIKyocera Taskalfa 3252ciAIKyocera Taskalfa 2553ciAI+12 | 9/7/2026 | 10/7/2026 | Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive information can be obtained. This affects… | |
| Pendiente de análisis | Alta (7.5) | 0.50% | — | Genetec Security CenterAI | 6/7/2026 | 7/7/2026 | A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unauthenticated attacker to access live video streams. | |
| Analizada | Alta (7.5) | 0.65% | — | Cisco Catalyst CenterCisco Catalyst Center Global Manager | 1/7/2026 | 17/9/2026 | This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device. |