Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.30% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Information is exposed to an Unauthorized Actor. | |
| Analizada | Crítica (9.6) | 0.26% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges. | |
| Analizada | Baja (3.3) | 0.09% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exposure of Sensitive Information because of Incompatible Policies. | |
| Analizada | Media (4.1) | 0.09% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is a Broken or Risky Cryptographic Algorithm. | |
| Analizada | Crítica (10) | 0.31% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges. | |
| Analizada | Media (5.5) | 0.44% | — | Oretnom23 Survey Application System | 12/11/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Survey Application System 1.0. This affects an unknown function of the file /view_survey.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.4) | 0.11% | — | Intel Rapid Storage Technology ApplicationAI | 11/11/2025 | 17/6/2026 | Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before version 20.0.1021 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local code execution. This… | |
| Aplazada | Alta (8.8) | 4.2% | 💥 PoC | Zohocorp Manageengine Applications ManagerAI | 11/11/2025 | 25/9/2026 | Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature. | |
| Aplazada | Media (5.3) | 0.46% | — | SAP Netweaver Application Server JavaAI | 11/11/2025 | 17/6/2026 | Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive… | |
| Aplazada | Baja (2.7) | 0.25% | — | SAP Netweaver Application Server FOR AbapAISAP Migration WorkbenchAISAP DX WorkbenchAI | 11/11/2025 | 17/6/2026 | Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files to the application server. An attacker could leverage this and upload a malicious file into the system. This results in a low impact on the… | |
| Aplazada | Media (4.3) | 0.23% | — | SAP Netweaver Application Server AbapAI | 11/11/2025 | 17/6/2026 | Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module in ABAP to retrieve restricted technical information from the system. This disclosure of environment details of the system could further assist… | |
| Analizada | Media (5.5) | 0.44% | — | Oretnom23 Survey Application System | 10/11/2025 | 7/10/2026 | A flaw has been found in SourceCodester Survey Application System 1.0. This impacts the function save_user/update_user of the file /LoginRegistration.php. Executing manipulation of the argument fullname can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.… | |
| Aplazada | Media (5.4) | 0.21% | — | Clear2pay Bank Visibility Application - Payment ExecutionAI | 28/10/2025 | 17/6/2026 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Clear2Pay Bank Visibility Application - Payment Execution 1.10.0.104 via the ID parameter in the URL. | |
| Aplazada | Alta (7.5) | 0.36% | — | Bessystem BES Application ServerAI | 28/10/2025 | 5/7/2026 | An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-resource" option in bes-web.xml. | |
| Analizada | Crítica (9.8) | 0.55% | — | IBM Maximo Application Suite | 28/10/2025 | 25/9/2026 | IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application. | |
| Aplazada | Alta (8.4) | 0.20% | — | I-O Data Device NAS Management ApplicationsAI | 23/10/2025 | 17/6/2026 | Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege. | |
| Analizada | Alta (7.5) | 0.32% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 8/10/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: System Configuration). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Analizada | Alta (8.1) | 0.33% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 8/10/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via… | |
| Analizada | Media (4.3) | 0.24% | — | Oracle Applications Framework | 21/10/2025 | 8/10/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Media (4.3) | 0.24% | — | Oracle Applications Framework | 21/10/2025 | 8/10/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Media (6.1) | 0.23% | — | Oracle Applications Manager | 21/10/2025 | 8/10/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Application Logging Interfaces). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications… | |
| Analizada | Crítica (9.8) | 0.47% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 8/10/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 8/10/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Media (6.5) | 0.33% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 8/10/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via… | |
| Analizada | Media (5.4) | 0.24% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 8/10/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… |