Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.1) | 0.45% | — | Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Analizada | Crítica (10) | 0.46% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/9/2026 | 28/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Analizada | Crítica (10) | 0.40% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/9/2026 | 28/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Analizada | Crítica (9.9) | 0.37% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/9/2026 | 28/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Aplazada | Alta (7.2) | 0.46% | — | Oracle Identity Manager ConnectorAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database Application Table). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Media (5.5) | 0.15% | — | Oracle Agile PLM Mcad ConnectorAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise… | |
| Aplazada | Alta (7.3) | 0.15% | — | Oracle Agile PLM Mcad ConnectorAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise… | |
| Aplazada | Media (5.5) | 0.15% | — | Oracle Agile PLM Mcad ConnectorAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Identity Manager Connector | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware… | |
| Analizada | Crítica (9.3) | 0.35% | — | Oracle Identity Manager Connector | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware… | |
| Analizada | Alta (8.3) | 0.31% | — | Oracle Identity Manager Connector | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware… | |
| Analizada | Alta (8.7) | 0.34% | — | Oracle Identity Manager Connector | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Identity Manager… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Identity Manager Connector | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager Connector… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Identity Manager Connector | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager… | |
| Pendiente de análisis | Alta (7.5) | 0.13% | — | Zscaler Client ConnectorAI | 14/9/2026 | 18/9/2026 | On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture. | |
| Pendiente de análisis | Alta (8.1) | 0.18% | — | Zscaler Client ConnectorAIGoogle AndroidAIGoogle ChromeosAI | 14/9/2026 | 18/9/2026 | An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls. | |
| Pendiente de análisis | Alta (8.1) | 0.38% | — | Zscaler Client ConnectorAI | 14/9/2026 | 18/9/2026 | A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process. | |
| Pendiente de análisis | Alta (7.8) | 0.20% | — | Auth0 AD Ldap ConnectorAI | 8/9/2026 | 10/9/2026 | The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account. | |
| Pendiente de análisis | Crítica (9) | 0.40% | — | Auth0 AD Ldap ConnectorAI | 8/9/2026 | 10/9/2026 | The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the… | |
| Pendiente de análisis | Media (6.7) | 0.18% | — | Auth0 AD Ldap ConnectorAI | 8/9/2026 | 10/9/2026 | The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints,… | |
| Pendiente de análisis | Alta (8.5) | 0.35% | — | Google Cloud Integration ConnectorsAI | 4/9/2026 | 8/9/2026 | A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on… | |
| Aplazada | Media (6.5) | 0.33% | — | Mountdev AI MCP Connector FOR WordpressAI | 3/9/2026 | 4/9/2026 | Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev AI MCP Connector for WordPress: from n/a through 1.6.5. | |
| Aplazada | Alta (7.1) | 0.25% | — | LeadconnectorAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. | |
| Pendiente de análisis | Media (5.9) | 0.23% | — | Mariadb Connector R2dbcAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport encryption because the AuthenticationPlugin interface has no capability for a plugin to require a secure connection. A… | |
| Pendiente de análisis | Media (5.9) | 0.49% | — | Mariadb Connector R2dbcAIMariadbAIMysqlAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption that the connection character set is UTF-8. A server can announce a mid-session change to character_set_client through the… |