Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
4639 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.14% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with logon to the… | |
| Analizada | Media (4.8) | 0.25% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Difficult to exploit vulnerability allows low privileged attacker with network… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Financial Services Customer Screening | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Customer Screening product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.1.2.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.8) | 0.29% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Difficult to exploit vulnerability allows low privileged attacker with network access via… | |
| Analizada | Media (6.5) | 0.39% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Alta (7.5) | 0.31% | 💥 PoC | Oracle Financial Services Analytical Applications Infrastructure | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Media (5.3) | 0.09% | — | Hcltech Bigfix Service Management | 21/4/2026 | 7/10/2026 | HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. An attacker with access to the network traffic can sniff packets from the connection and uncover the data. | |
| Analizada | Alta (8.2) | 0.19% | — | Hcltech Bigfix Service Management | 21/4/2026 | 7/10/2026 | HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing… | |
| Analizada | Crítica (9.9) | 5.6% | — | Cisco Identity Services Engine | 15/4/2026 | 29/6/2026 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to… | |
| Pendiente de análisis | Crítica (9.8) | 0.52% | — | Cisco Webex ServicesAI | 15/4/2026 | 17/6/2026 | A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an… | |
| Analizada | Crítica (9.9) | 6.0% | 💥 PoC | Cisco Identity Services Engine | 15/4/2026 | 8/7/2026 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to… | |
| Analizada | Media (4.8) | 0.17% | — | Cisco Identity Services Engine | 15/4/2026 | 2/7/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management… | |
| Analizada | Media (4.9) | 6.5% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 15/4/2026 | 25/9/2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper… | |
| Analizada | Crítica (9.9) | 10% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 15/4/2026 | 25/9/2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient… | |
| Analizada | Media (6) | 0.50% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 15/4/2026 | 25/9/2026 | A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root. This… | |
| Analizada | Media (5.4) | 0.13% | — | Lenovo Service Bridge | 15/4/2026 | 24/8/2026 | A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges. | |
| Pendiente de análisis | Alta (7.5) | 0.36% | — | DRC Central Office ServicesAI | 14/4/2026 | 24/7/2026 | Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) allows an attacker to modify the server's configuration file, potentially leading to mass data exfiltration, malicious traffic interception, or disruption of testing services. | |
| Analizada | Crítica (9.8) | 0.34% | — | Foxit PDF Services API | 13/4/2026 | 7/7/2026 | An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls,… | |
| Analizada | Alta (7.5) | 6.6% | ⚠ Explotación activa💥 Exploit | Apache TomcatRedhat Jboss WEB ServerRedhat Enterprise LinuxRedhat Enterprise Linux ELS+3 | 9/4/2026 | 21/9/2026 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. | |
| Analizada | Media (6.4) | 0.14% | — | Redhat Openshift Update Service | 8/4/2026 | 24/7/2026 | A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root… | |
| Analizada | Crítica (9.8) | 0.90% | — | Microsoft Azure Kubernetes Service | 3/4/2026 | 24/7/2026 | Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.1) | 0.25% | — | Miniorange Saml SSO - Service Provider | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - Service Provider allows Cross-Site Scripting (XSS).This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.3. | |
| Analizada | Media (6.9) | 0.19% | — | Lizardsystems Terminal Services Manager | 21/3/2026 | 17/6/2026 | Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during computer addition, causing… | |
| Analizada | Alta (8.8) | 0.46% | — | Doobidoo Mcp-memory-service | 20/3/2026 | 17/6/2026 | mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the application configures FastAPI's CORSMiddleware with allow_origins=['*'], allow_credentials=True, allow_methods=["*"], and allow_headers=["*"]. The… |