Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
312 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6) | 0.38% | — | Limesurvey Community EditionAI | 14/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list. | |
| Aplazada | Alta (8.5) | 0.53% | — | Limesurvey Community EditionAI | 14/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding. | |
| Aplazada | Media (5.1) | 0.31% | — | Saurus CMS Community EditionAI | 13/8/2026 | 31/8/2026 | Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or relative path enforcement. Attackers can… | |
| Aplazada | Media (6.5) | 0.22% | — | FluentcommunityAI | 13/8/2026 | 14/8/2026 | Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Documize CommunityAI | 5/8/2026 | 26/8/2026 | Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0), without comparing it to any server-stored value. | |
| Analizada | Media (5.9) | 0.27% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Trading Community | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Trading Community | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful… | |
| Analizada | Media (6.5) | 0.27% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.… | |
| Analizada | Media (6.5) | 0.28% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.… | |
| Analizada | Alta (8.2) | 0.35% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.… | |
| Analizada | Alta (7.1) | 0.28% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Person Data). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.… | |
| Analizada | Media (6.6) | 0.40% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student… | |
| Analizada | Media (5.3) | 0.34% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.… | |
| Analizada | Media (5.9) | 0.35% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus Community.… | |
| Analizada | Media (6.5) | 0.39% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Communication). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Higher Ed Statistics Agency - UK HESA). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Australian Features). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Student… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS… | |
| Pendiente de análisis | Alta (8) | 0.40% | — | Kubeflow Community DistributionAIKubeflow PlatformAI | 21/7/2026 | 23/7/2026 | Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from any user of the Kubeflow UI or APIs,… | |
| Aplazada | Media (5.3) | 0.49% | — | Pallets Community Flask Security TOOAI | 20/7/2026 | 23/7/2026 | Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentication flow can mark a session as fresh after verifying an OAuth account that belongs to a different user. If an attacker can operate an already-authenticated but stale victim session, they can… | |
| Aplazada | Alta (7.7) | 2.3% | — | Luci-app-tailscale-communityAI | 29/6/2026 | 14/7/2026 | luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-controlled loginserver and loginserver_authkey parameters are improperly quoted within a… |