Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
5400 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.38% | — | IBM Cloud PAK System | 28/7/2026 | 19/8/2026 | IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files. | |
| Aplazada | Media (5.8) | 0.40% | — | Alibabacloud RDS Openapi MCP ServerAI | 28/7/2026 | 28/7/2026 | Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default. | |
| Analizada | Crítica (10) | 1.0% | ⚠ Explotación activa | Arista Velocloud Orchestrator | 27/7/2026 | 28/7/2026 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.… | |
| Pendiente de análisis | Alta (8.7) | 0.45% | — | Google Cloud LookerAI | 24/7/2026 | 27/7/2026 | A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to administrative account takeover using a maliciously crafted… | |
| Pendiente de análisis | Media (5.3) | 0.44% | — | Oracle JavaAIRedhat Cloudforms SystemAI | 23/7/2026 | 24/7/2026 | An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wgstart WgcloudAI | 21/7/2026 | 22/7/2026 | SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file | |
| Analizada | Baja (3.1) | 0.22% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse. | |
| Analizada | Baja (3.1) | 0.15% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack. | |
| Analizada | Baja (2.6) | 0.15% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens. | |
| Analizada | Baja (2.2) | 0.28% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system. | |
| Analizada | Baja (3.1) | 0.25% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security. | |
| Analizada | Baja (2.2) | 0.26% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions. | |
| Analizada | Media (6.5) | 0.28% | — | Hcltech Dryice Mycloud | 21/7/2026 | 3/8/2026 | HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks. | |
| Pendiente de análisis | Alta (8.5) | 0.35% | — | Google Cloud Firebase StudioAIGoogle Cloud PlatformAI | 17/7/2026 | 17/7/2026 | Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on 15 April 2026, and no customer action is… | |
| Aplazada | Alta (7.5) | 0.24% | — | Seppmail Secure Email GatewayAISeppmail CloudAI | 17/7/2026 | 17/7/2026 | SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header. | |
| Aplazada | Media (6.5) | 0.51% | — | Pcloud WP BackupAI | 17/7/2026 | 17/7/2026 | The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract force generation of a full-site backup… | |
| Aplazada | Crítica (9.3) | 0.52% | — | SAP Cloud Application Programming ModelAICap-js Db-serviceAISqliteAISupabase PostgresAI | 15/7/2026 | 15/7/2026 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were… | |
| Analizada | Media (6.5) | 0.32% | — | SplunkSplunk Cloud Platform | 15/7/2026 | 24/7/2026 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could view stored credential hashes when they access the… | |
| Analizada | Alta (7.2) | 0.57% | — | SplunkSplunk Cloud Platform | 15/7/2026 | 24/7/2026 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24, a user who holds a role that contains the `edit_local_apps` and `install_apps` capabilities could cause a legitimate app installation to… | |
| Analizada | Alta (8.3) | 0.18% | — | SplunkSplunk Cloud Platform | 15/7/2026 | 24/7/2026 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_deployment_server` capability into running arbitrary Search Processing… | |
| En análisis | Alta (7.5) | 0.47% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Alta (7.5) | 0.47% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Crítica (9.8) | 0.19% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Crítica (9.8) | 0.46% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Alta (7.5) | 0.47% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… |