Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
5082 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.4) | 0.17% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI | 16/9/2026 | 18/9/2026 | A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This… | |
| Pendiente de análisis | Alta (8.6) | 0.40% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI | 16/9/2026 | 18/9/2026 | A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a… | |
| Pendiente de análisis | Media (5.3) | 0.49% | — | Cisco Adaptive Security ApplianceAICisco Threat DefenseAI | 16/9/2026 | 18/9/2026 | A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability… | |
| Pendiente de análisis | Media (5.8) | 0.41% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI | 16/9/2026 | 18/9/2026 | A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability… | |
| Pendiente de análisis | Crítica (9.9) | 0.34% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | The vulnerabilities tracked by CVE-2026-20330 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707. | |
| Pendiente de análisis | Crítica (9.9) | 0.45% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | The vulnerabilities tracked by CVE-2026-20329 are related to issues concerning improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703. | |
| Pendiente de análisis | Crítica (9.6) | 0.23% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | The vulnerabilities tracked by CVE-2026-20331 are related to the failure of protection mechanisms issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-693. | |
| Analizada | Alta (7.5) | 0.48% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute code outside the… | |
| Analizada | Alta (7.5) | 0.29% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins… | |
| Analizada | Alta (8) | 0.61% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to… | |
| Modificada | Alta (8.5) | 0.62% | — | Jenkins Script Security | 16/9/2026 | 26/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to execute code outside the sandbox if a suitable class is present on… | |
| Analizada | Alta (8.8) | 0.56% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitrary AST transformation at compile time, bypassing the sandbox protection and… | |
| Analizada | Alta (8.8) | 0.63% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allowing attackers with permission to define and run sandboxed scripts,… | |
| Analizada | Alta (8.8) | 0.63% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection… | |
| Analizada | Alta (8.8) | 0.63% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface method, allowing attackers with permission to define and run sandboxed… | |
| Pendiente de análisis | Crítica (10) | 0.48% | — | Oracle Platform Security FOR JavaAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Pendiente de análisis | Alta (8.1) | 0.37% | — | Oracle Platform Security FOR JavaAIOracle Fusion MiddlewareAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | Oracle Platform Security FOR JavaAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Platform… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle Platform Security FOR JavaAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle Platform Security FOR JavaAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle… | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (8.2) | 0.28% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (7.1) | 0.25% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication… | |
| Pendiente de análisis | Alta (7.5) | 0.16% | — | IBM Security Verify Identity Access Reverse ProxyAI | 15/9/2026 | 16/9/2026 | IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Pendiente de análisis | Media (6.5) | 0.17% | — | IBM Security Verify Identity AccessAI | 15/9/2026 | 19/9/2026 | IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services. |