Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

3323 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.7)0.12%—HCL ConnectionsAI26/8/202628/8/2026
HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to information disclosure or security bypass.
Pendiente de análisisAlta (7.5)0.24%—Vanderbilt Industries Acre Security Spc5300AIVanderbilt Industries SPC Connect PROAI26/8/20269/9/2026
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session.
AplazadaCrítica (9)0.37%—UI Unifi Connect Display Cast PROAI26/8/202628/8/2026
A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device.
AplazadaAlta (8.2)0.39%—UI Unifi ConnectAI26/8/202628/8/2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the UniFi Connect Application.
AplazadaMedia (4.2)0.26%—Doorkeeper Openid ConnectAI25/8/20269/9/2026
Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this…
Pendiente de análisisCrítica (9.1)0.66%—Zscaler Client ConnectorAI24/8/202628/8/2026
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
Pendiente de análisisAlta (8.8)0.15%—Zscaler Client ConnectorAI24/8/202628/8/2026
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.
Pendiente de análisisAlta (8.4)0.18%—Zscaler Client ConnectorAI24/8/202628/8/2026
A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.
Pendiente de análisisAlta (8.8)0.48%—Zscaler Client ConnectorAI24/8/202628/8/2026
A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.
Pendiente de análisisCrítica (9.1)0.53%—Zscaler Client ConnectorAIZscaler Client Connector PortalAI24/8/202628/8/2026
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
AplazadaMedia (5.5)2.1%—Chenhg5 Cc-connectAI19/8/202620/8/2026
A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the function shellExecCommand of the file core/engine.go of the component Management API. Such manipulation of the argument exec leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available…
AplazadaMedia (5.5)0.54%—Chenhg5 Cc-connectAI19/8/202620/8/2026
A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the function Authenticate of the file core/webhook.go. The manipulation of the argument exec results in code injection. The attack may be performed from remote. The exploit has been made public and could be used. The…
AnalizadaAlta (7.4)0.24%—Splunk Connect FOR Kafka19/8/202624/8/2026
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from the connector when Kerberos authentication is used with Hypertext Transfer Protocol (HTTP) Event Collector in Splunk Enterprise. The vulnerability is possible because…
AnalizadaAlta (8.2)0.41%—Splunk Connect FOR Kafka19/8/202624/8/2026
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a non-secure Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise that causes the connector to send authentication credentials…
AnalizadaMedia (5.9)0.38%—Splunk Connect FOR Kafka19/8/202624/8/2026
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp extraction with a crafted regular expression and matching event data to block a Kafka Connect worker thread, stopping event delivery for the…
AnalizadaMedia (5.9)0.38%—Splunk Connect FOR Kafka19/8/202624/8/2026
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise could cause the connector to retry failed event batches…
Pendiente de análisisMedia (4.3)0.19%—Attack Analyzer Connector FOR Splunk SoarAI19/8/202620/8/2026
In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking either the detonate file or detonate url action, because the action's archive_password parameter is not masked and is shown in…
AnalizadaBaja (3.3)0.16%—Oracle Agile PLM Mcad Connector18/8/202625/8/2026
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise…
AnalizadaMedia (4.8)0.25%—Oracle Agile PLM Mcad Connector18/8/202625/8/2026
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks…
AnalizadaMedia (5.3)0.34%—Oracle Agile PLM Mcad Connector18/8/202625/8/2026
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of…
AnalizadaMedia (6.8)0.17%—Oracle Mysql Connector/odbc18/8/20262/9/2026
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful…
AnalizadaBaja (1.8)0.13%—Oracle Agile PLM Mcad Connector18/8/202624/8/2026
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise…
AnalizadaBaja (2.5)0.12%—Oracle Agile PLM Mcad Connector18/8/202624/8/2026
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise…
AnalizadaBaja (1.9)0.13%—Oracle Agile PLM Mcad Connector18/8/202624/8/2026
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise…
AnalizadaBaja (3.7)0.23%—Oracle Agile PLM Mcad Connector18/8/202624/8/2026
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle…