Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
686 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.28% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. While… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Hyperion Infrastructure Technology | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure… | |
| Analizada | Media (5.3) | 0.32% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful… | |
| Analizada | Media (5.3) | 0.30% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.… | |
| Analizada | Media (6.7) | 0.17% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.… | |
| Analizada | Alta (8.1) | 0.38% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful… | |
| Analizada | Alta (7.1) | 0.38% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. While the… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful… | |
| Analizada | Media (6.5) | 0.27% | — | Oracle Hyperion Financial Management | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.… | |
| Analizada | Alta (7.5) | 0.44% | — | Oracle Hyperion Infrastructure Technology | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Hyperion Financial Management | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful… | |
| Analizada | Media (6) | 0.18% | — | Oracle Hyperion Financial Management | 18/8/2026 | 21/9/2026 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to… | |
| Aplazada | Alta (7.5) | 1.1% | — | Nasa HypercpAI | 10/8/2026 | 28/8/2026 | An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept or spoof responses from oceandata.sci.gsfc.nasa.gov to execute arbitrary system commands on the researcher's workstation. | |
| Aplazada | Media (6.3) | 0.41% | — | HyperdxAI | 20/7/2026 | 23/7/2026 | HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a caller-controlled host parameter to the ClickHouse proxy test endpoint with no URL validation or allowlist enforcement. Attackers can… | |
| Aplazada | Media (5.3) | 0.40% | — | HyperdxAI | 20/7/2026 | 23/7/2026 | HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by supplying a caller-controlled URL to the webhook test endpoint. Attackers can bypass the insufficient hostname blacklist… | |
| Aplazada | Alta (8.4) | 0.18% | — | Hyper SBI 2AI | 15/7/2026 | 15/7/2026 | The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer. | |
| Pendiente de análisis | Media (6) | 0.33% | — | Cisco HyperflexAI | 14/7/2026 | 15/7/2026 | An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service. | |
| Aplazada | Alta (8.9) | 0.18% | — | Cloudhypervisor Cloud HypervisorAI | 10/6/2026 | 23/7/2026 | Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can cause a use-after-free in the cloud-hypervisor process by submitting two virtio-block descriptor chains that reuse the same head_index while asynchronous block I/O is enabled (e.g. io_uring, aio).… | |
| Aplazada | Media (5.5) | 0.15% | — | Hyperledger Fabric-chaincode-javaAI | 8/6/2026 | 23/7/2026 | fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An… | |
| Analizada | Media (4.3) | 0.28% | — | Synology Hyper Backup | 3/6/2026 | 22/7/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors. | |
| Analizada | Media (4.1) | 0.30% | — | Synology Hyper Backup | 3/6/2026 | 22/7/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified… |