Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

3834 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.8)0.14%—Oracle Business Intelligence Enterprise EditionAI15/9/202617/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business…
AplazadaAlta (8.1)0.37%—Oracle Business Intelligence Enterprise EditionAI15/9/202617/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
AplazadaCrítica (9.9)0.42%—Oracle Business Intelligence Enterprise EditionAI15/9/202617/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence…
AplazadaAlta (7.2)0.46%—Oracle Business Intelligence Enterprise EditionAI15/9/202617/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business…
AplazadaMedia (6.5)0.34%—Oracle E-business SuiteAIOracle Process Manufacturing IntelligenceAI15/9/202617/9/2026
Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Process…
AplazadaAlta (7.1)0.28%—Oracle Project IntelligenceAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.…
Pendiente de análisisMedia (6.8)0.30%—Oracle HR IntelligenceAIOracle E-business SuiteAI15/9/202616/9/2026
Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HR Intelligence. Successful…
AplazadaAlta (7.8)0.14%—Oracle Business Intelligence Enterprise EditionAI15/9/202617/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Machine Learning). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business…
AplazadaAlta (7.1)0.23%—Oracle Business Intelligence Enterprise EditionAI15/9/202621/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
AplazadaAlta (8.5)0.29%—Oracle Business Intelligence Enterprise EditionAI15/9/202621/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Actions). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business…
AplazadaAlta (8.9)0.33%—Oracle Business Intelligence Enterprise EditionAI15/9/202618/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to…
AplazadaAlta (7.7)0.37%—Oracle Business Intelligence Enterprise EditionAI15/9/202622/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise…
AplazadaAlta (8.3)0.37%—Oracle Business Intelligence Enterprise EditionAI15/9/202618/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence…
Pendiente de análisisCrítica (9.8)0.48%—Oracle Business Intelligence Enterprise EditionAI15/9/202622/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence…
AplazadaAlta (7.5)0.39%—Oracle Business Intelligence Enterprise EditionAI15/9/202621/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
AplazadaAlta (8.1)0.35%—Oracle Project IntelligenceAIOracle E-business SuiteAI15/9/202618/9/2026
Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.…
AplazadaCrítica (9.8)0.80%—Intel Uefi FirmwareAI14/9/202630/9/2026
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT = 9 and can obtain 511 entries for the 510-element Sd->mCLen heap array because…
AplazadaCrítica (9.8)0.80%—Intel Uefi FirmwareAI14/9/202630/9/2026
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that bit-length values read from a crafted Tiano or EFI compressed firmware bitstream remain within the…
Pendiente de análisisMedia (6.5)0.25%—SAP Manufacturing Integration AND IntelligenceAI8/9/20268/9/2026
Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful…
Pendiente de análisisBaja (3.3)0.15%—Jetbrains Intellij IdeaAI7/9/20268/9/2026
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace
Pendiente de análisisAlta (7.8)0.18%—Jetbrains Intellij IdeaAI7/9/20269/9/2026
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
Pendiente de análisisBaja (3.3)0.14%—Jetbrains Intellij IdeaAI7/9/20268/9/2026
In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching
Pendiente de análisisAlta (8.4)0.21%—Jetbrains Intellij IdeaAI7/9/20269/9/2026
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
Pendiente de análisisBaja (2.8)0.39%—Jetbrains Intellij IdeaAI7/9/20268/9/2026
In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log
AplazadaMedia (6.9)0.43%—FlowintelAI27/8/202628/8/2026
Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That does not perform WTForms field validation; it merely constructs a validator object. Consequently, malformed attacker-controlled email input could continue through the login process and be written to…
Orbitaley — Vulnerabilidades