Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

4639 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)1.0%—Oracle Identity ManagerOracle WEB Services Manager20/3/202617/6/2026
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability…
AnalizadaAlta (8.1)0.27%—Devolutions HUB Reporting Service18/3/202617/6/2026
Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.
Pendiente de análisisAlta (8.8)0.46%—Microsoft Dynamics 365 Customer EngagementAIMicrosoft SQL Server Reporting ServicesAI18/3/202617/6/2026
Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; this is then processed by the SQL Server Reporting Service. An account with the privilege Add Reporting Services Reports…
AnalizadaAlta (7.4)0.23%—Opentext Zenworks Service Desk18/3/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Site Scripting (XSS). The vulnerability could allow an attacker to execute arbitrary JavaScript leading to unauthorized actions on behalf of the user.This issue affects…
AplazadaMedia (6.5)0.35%—Powersync ServiceAI10/3/202617/6/2026
PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determining which data to sync to users. Depending on the sync stream configuration, this could result in authenticated users…
Pendiente de análisisMedia (6.1)0.22%—SAP Business ONE JOB ServiceAI10/3/202617/6/2026
Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon user interaction could result in a DOM-based Cross-Site Scripting (XSS) vulnerability. This issue had a low impact on…
AnalizadaCrítica (9.8)0.36%—Miazzy Oa-font-service9/3/202617/6/2026
An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-front-service master.
AnalizadaMedia (5.3)0.43%—Doobidoo Mcp-memory-service7/3/202617/6/2026
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/detailed endpoint returns detailed system information including OS version, Python version, CPU count, memory totals, disk usage, and the full database filesystem path. When…
AnalizadaCrítica (9.8)1.1%—Microsoft Payment Orchestrator Service5/3/202617/6/2026
Payment Orchestrator Service Elevation of Privilege Vulnerability
AplazadaAlta (8.8)0.62%💥 PoCAranda Service Desk WEB EditionAI5/3/202617/6/2026
An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded files. An authenticated user can upload a crafted web.config file by sending a crafted POST request to /ASDKAPI/api/v8.6/item/addfile, which is processed by…
AplazadaAlta (8.1)0.58%—Axiomthemes AC ServicesAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme window-ac-services allows PHP Local File Inclusion.This issue affects AC Services | HVAC, Air Conditioning &…
AnalizadaMedia (5.3)0.37%💥 PoCMariadbAmazon Aurora MysqlAmazon Relational Database Service3/3/202614/7/2026
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.
AplazadaCrítica (9.2)0.59%💥 PoCServicenow AI PlatformAIServicenow SandboxAI25/2/202617/6/2026
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow Sandbox. ServiceNow addressed this vulnerability by deploying a security update to…
AnalizadaBaja (2.7)0.18%—Ens.domains Ethereum Name Service25/2/202617/6/2026
Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In versions 1.6.2 and prior, the `RSASHA256Algorithm` and `RSASHA1Algorithm` contracts fail to validate PKCS#1 v1.5 padding structure when verifying RSA signatures. The contracts only check if the last 32…
AnalizadaAlta (7.5)0.59%—Nvidia Delegated License Service24/2/202617/6/2026
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentication issue. A successful exploit of this vulnerability might lead to information disclosure.
ModificadaMedia (5.8)0.10%—Genetec Update Service24/2/202617/6/2026
Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.
ModificadaMedia (5.8)0.09%—Genetec Update Service24/2/202617/6/2026
Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin privileged, Windows user could exploit this vulnerability to gain elevated privileges in the Genetec Update Service. Could be combined with CVE-2025-1789 to achieve low privilege escalation.
AplazadaAlta (8.3)7.7%—Zohocorp Manageengine Adselfservice PlusAI23/2/202617/6/2026
Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.
AnalizadaMedia (5.3)0.25%—Opentext Directory Services19/2/202617/6/2026
User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning. The vulnerability could be exploited by a bad actor to inject manipulated text into the OpenText application, potentially misleading users. This issue affects Directory Services: from…
AnalizadaCrítica (9.3)1.1%—Hyland Alfresco Transform ServiceHyland Alfresco Transform Core19/2/202614/7/2026
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.
AnalizadaMedia (6.9)0.65%—Hyland Alfresco Transform ServiceHyland Alfresco Transform Core19/2/202614/7/2026
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality.
AnalizadaAlta (8.8)0.52%—Hyland Alfresco Transform ServiceHyland Alfresco Transform Core19/2/202614/7/2026
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.
AnalizadaAlta (8.7)0.71%💥 PoCHyland Alfresco Content Services19/2/202617/6/2026
Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" endpoint, thus leading to the disclosure of sensitive configuration files.
AplazadaCrítica (9.8)0.57%—Inrove Software AND Internet Services Bieticaret CMSAI19/2/202617/6/2026
Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting. This issue affects BiEticaret CMS: from 2.1.13 through 19022026. NOTE: The vendor was contacted early about this…
AplazadaAlta (7.3)0.22%—Mecode Informatics AND Engineering Services LTD EnvantyAI19/2/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection. This issue affects Envanty: before 1.0.6. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The vulnerability was learned to be…