Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.13% | — | Oracle Peoplesoft Lease Administration | 18/8/2026 | 10/9/2026 | Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (component: Lease Administration). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Lease… | |
| Aplazada | Media (6.3) | 0.17% | — | Ministry OF Justice Uyap Document EditorAI | 12/8/2026 | 26/8/2026 | Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking. This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17. | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Jboss MarshallingAIInfinispanAI | 11/8/2026 | 25/9/2026 | A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node. | |
| Analizada | Media (6.5) | 0.45% | — | Dell Openmanage Server Administrator | 7/8/2026 | 8/8/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Crítica (9.8) | 0.53% | — | Dell Openmanage Server Administrator | 7/8/2026 | 8/8/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Aplazada | Media (5.4) | 0.24% | — | Revenue Administration Turkiye E-signatureAI | 7/8/2026 | 26/8/2026 | Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0. | |
| Aplazada | Alta (8.8) | 0.21% | — | Prestashop TotadministrativemandateAI | 31/7/2026 | 31/8/2026 | PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link. | |
| Aplazada | Alta (7.6) | 0.38% | — | AdministratorAI | 26/6/2026 | 26/6/2026 | Administrator SQL Injection in Popup box <= 6.0.1 versions. | |
| Aplazada | Media (4.3) | 0.21% | — | Inisev Social Media AND Share IconsAI | 17/6/2026 | 1/10/2026 | : Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6. | |
| Aplazada | Alta (8.1) | 1.9% | — | Kanishka-linux ReminiscenceAI | 15/6/2026 | 17/6/2026 | An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input. | |
| Aplazada | Crítica (9.8) | 2.8% | — | Kanishka-linux ReminiscenceAI | 15/6/2026 | 17/6/2026 | An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input. | |
| Aplazada | Baja (1.9) | 0.11% | — | Bytedance InfinistoreAI | 5/6/2026 | 23/7/2026 | A vulnerability was found in bytedance InfiniStore up to 0.2.33. The impacted element is the function purge_kv_map in the library /src/infinistore.h of the component KV Map Handler. Performing a manipulation results in inefficient algorithmic complexity. The attack requires a local approach. The exploit has been made… | |
| Aplazada | Alta (8.2) | 0.28% | — | Talend Administration CenterAI | 20/5/2026 | 23/7/2026 | A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio update URL. This issue was resolved in a patch, which is already available. | |
| Aplazada | Media (5.4) | 0.23% | — | Talend Administration CenterAI | 20/5/2026 | 23/7/2026 | A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload that can be triggered by a different user. | |
| Aplazada | Media (6.9) | 0.15% | — | Amministrazione-apertaAI | 10/5/2026 | 24/7/2026 | WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in the open parameter. Attackers can supply file paths through the open GET parameter in dispatcher.php to include and read… | |
| Analizada | Media (5.3) | 0.18% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers. | |
| Aplazada | Alta (8.7) | 0.31% | — | Inisev Backup MigrationAI | 5/5/2026 | 17/6/2026 | WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated attackers to download complete database backups by accessing predictable file paths. Attackers can enumerate backup directories through configuration files and complete logs, then construct direct… | |
| Pendiente de análisis | Alta (7.5) | 1.2% | 💥 PoC | Apache CamelAIInfinispanAI | 22/4/2026 | 23/9/2026 | A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over… | |
| En análisis | Media (4.3) | 0.18% | — | Hitachi OPS Center Administrator | 25/3/2026 | 12/8/2026 | Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.2.0 before 11.0.8. | |
| Pendiente de análisis | Alta (8.7) | 0.38% | — | Tibco Activematrix BusinessworksAITibco Enterprise AdministratorAI | 24/3/2026 | 17/6/2026 | Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour. | |
| Aplazada | Media (4.3) | 0.18% | — | Lobot Slider AdministratorAI | 21/3/2026 | 17/6/2026 | The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.0. This is due to missing or incorrect nonce validation on the fourty_slider_options_page function. This makes it possible for unauthenticated attackers to modify plugin slider-page… | |
| Analizada | Baja (1.9) | 0.21% | — | Minisat | 18/2/2026 | 17/6/2026 | A weakness has been identified in niklasso minisat up to 2.2.0. This issue affects the function Solver::value in the library core/SolverTypes.h of the component DIMACS File Parser. This manipulation of the argument variable index with the input 2147483648 causes out-of-bounds read. The attack needs to be launched… | |
| Aplazada | Media (4.6) | 0.17% | — | Kaba 9300 AdministrationAI | 26/1/2026 | 17/6/2026 | The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation. | |
| Aplazada | Alta (7.5) | 0.76% | — | Administrative ShortcodesAI | 24/1/2026 | 17/6/2026 | The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.3.4 via the 'slug' attribute of the 'get_template' shortcode. This is due to insufficient path validation on user-supplied input passed to the get_template_part() function. This makes it… |