Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
4639 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.0% | — | Oracle Identity ManagerOracle WEB Services Manager | 20/3/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability… | |
| Analizada | Alta (8.1) | 0.27% | — | Devolutions HUB Reporting Service | 18/3/2026 | 17/6/2026 | Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification. | |
| Pendiente de análisis | Alta (8.8) | 0.46% | — | Microsoft Dynamics 365 Customer EngagementAIMicrosoft SQL Server Reporting ServicesAI | 18/3/2026 | 17/6/2026 | Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; this is then processed by the SQL Server Reporting Service. An account with the privilege Add Reporting Services Reports… | |
| Analizada | Alta (7.4) | 0.23% | — | Opentext Zenworks Service Desk | 18/3/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Site Scripting (XSS). The vulnerability could allow an attacker to execute arbitrary JavaScript leading to unauthorized actions on behalf of the user.This issue affects… | |
| Aplazada | Media (6.5) | 0.35% | — | Powersync ServiceAI | 10/3/2026 | 17/6/2026 | PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determining which data to sync to users. Depending on the sync stream configuration, this could result in authenticated users… | |
| Pendiente de análisis | Media (6.1) | 0.22% | — | SAP Business ONE JOB ServiceAI | 10/3/2026 | 17/6/2026 | Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon user interaction could result in a DOM-based Cross-Site Scripting (XSS) vulnerability. This issue had a low impact on… | |
| Analizada | Crítica (9.8) | 0.36% | — | Miazzy Oa-font-service | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-front-service master. | |
| Analizada | Media (5.3) | 0.43% | — | Doobidoo Mcp-memory-service | 7/3/2026 | 17/6/2026 | mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/detailed endpoint returns detailed system information including OS version, Python version, CPU count, memory totals, disk usage, and the full database filesystem path. When… | |
| Analizada | Crítica (9.8) | 1.1% | — | Microsoft Payment Orchestrator Service | 5/3/2026 | 17/6/2026 | Payment Orchestrator Service Elevation of Privilege Vulnerability | |
| Aplazada | Alta (8.8) | 0.62% | 💥 PoC | Aranda Service Desk WEB EditionAI | 5/3/2026 | 17/6/2026 | An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded files. An authenticated user can upload a crafted web.config file by sending a crafted POST request to /ASDKAPI/api/v8.6/item/addfile, which is processed by… | |
| Aplazada | Alta (8.1) | 0.58% | — | Axiomthemes AC ServicesAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme window-ac-services allows PHP Local File Inclusion.This issue affects AC Services | HVAC, Air Conditioning &… | |
| Analizada | Media (5.3) | 0.37% | 💥 PoC | MariadbAmazon Aurora MysqlAmazon Relational Database Service | 3/3/2026 | 14/7/2026 | In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged. | |
| Aplazada | Crítica (9.2) | 0.59% | 💥 PoC | Servicenow AI PlatformAIServicenow SandboxAI | 25/2/2026 | 17/6/2026 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow Sandbox. ServiceNow addressed this vulnerability by deploying a security update to… | |
| Analizada | Baja (2.7) | 0.18% | — | Ens.domains Ethereum Name Service | 25/2/2026 | 17/6/2026 | Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In versions 1.6.2 and prior, the `RSASHA256Algorithm` and `RSASHA1Algorithm` contracts fail to validate PKCS#1 v1.5 padding structure when verifying RSA signatures. The contracts only check if the last 32… | |
| Analizada | Alta (7.5) | 0.59% | — | Nvidia Delegated License Service | 24/2/2026 | 17/6/2026 | NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentication issue. A successful exploit of this vulnerability might lead to information disclosure. | |
| Modificada | Media (5.8) | 0.10% | — | Genetec Update Service | 24/2/2026 | 17/6/2026 | Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system. | |
| Modificada | Media (5.8) | 0.09% | — | Genetec Update Service | 24/2/2026 | 17/6/2026 | Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin privileged, Windows user could exploit this vulnerability to gain elevated privileges in the Genetec Update Service. Could be combined with CVE-2025-1789 to achieve low privilege escalation. | |
| Aplazada | Alta (8.3) | 7.7% | — | Zohocorp Manageengine Adselfservice PlusAI | 23/2/2026 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option. | |
| Analizada | Media (5.3) | 0.25% | — | Opentext Directory Services | 19/2/2026 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning. The vulnerability could be exploited by a bad actor to inject manipulated text into the OpenText application, potentially misleading users. This issue affects Directory Services: from… | |
| Analizada | Crítica (9.3) | 1.1% | — | Hyland Alfresco Transform ServiceHyland Alfresco Transform Core | 19/2/2026 | 14/7/2026 | Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality. | |
| Analizada | Media (6.9) | 0.65% | — | Hyland Alfresco Transform ServiceHyland Alfresco Transform Core | 19/2/2026 | 14/7/2026 | Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality. | |
| Analizada | Alta (8.8) | 0.52% | — | Hyland Alfresco Transform ServiceHyland Alfresco Transform Core | 19/2/2026 | 14/7/2026 | Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal. | |
| Analizada | Alta (8.7) | 0.71% | 💥 PoC | Hyland Alfresco Content Services | 19/2/2026 | 17/6/2026 | Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" endpoint, thus leading to the disclosure of sensitive configuration files. | |
| Aplazada | Crítica (9.8) | 0.57% | — | Inrove Software AND Internet Services Bieticaret CMSAI | 19/2/2026 | 17/6/2026 | Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting. This issue affects BiEticaret CMS: from 2.1.13 through 19022026. NOTE: The vendor was contacted early about this… | |
| Aplazada | Alta (7.3) | 0.22% | — | Mecode Informatics AND Engineering Services LTD EnvantyAI | 19/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection. This issue affects Envanty: before 1.0.6. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The vulnerability was learned to be… |