Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
8556 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Peoplesoft Enterprise PT Peopletools | 17/6/2026 | 24/6/2026 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Peoplesoft Enterprise PT Peopletools | 17/6/2026 | 24/6/2026 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Peoplesoft Enterprise PT Peopletools | 17/6/2026 | 24/6/2026 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Application Server). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT… | |
| Analizada | Alta (8.2) | 0.35% | — | Oracle Peoplesoft Enterprise PT Peopletools | 17/6/2026 | 24/6/2026 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT… | |
| Analizada | Alta (8.4) | 0.19% | — | Oracle Peoplesoft Enterprise PT Peopletools | 17/6/2026 | 24/6/2026 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PT PeopleTools… | |
| Analizada | Alta (8.7) | 0.34% | — | Oracle Peoplesoft Enterprise PT Peopletools | 17/6/2026 | 24/6/2026 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. While… | |
| Analizada | Alta (8.1) | 0.25% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 17/6/2026 | A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the… | |
| Analizada | Media (6.1) | 0.16% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 17/6/2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by… | |
| Analizada | Media (5.6) | 0.21% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 18/6/2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a… | |
| Modificada | Media (5.5) | 0.19% | — | Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux | 13/6/2026 | 21/9/2026 | Se encontró una vulnerabilidad de inyección de contenido en los scripts del gestor de eventos post-creación de ABRT en libreport. El script de evento consulta el registro de systemd en busca de entradas de registro que coincidan con el proceso bloqueado y escribe los resultados en archivos en el directorio de volcado… | |
| Modificada | Alta (7.8) | 0.23% | — | Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux | 13/6/2026 | 21/9/2026 | Una vulnerabilidad de seguimiento de enlaces simbólicos fue encontrada en los scripts del gestor de eventos post-creación de ABRT en libreport. Los scripts de eventos escriben archivos de salida usando redirecciones de shell sin la bandera O_NOFOLLOW. Si el archivo objetivo es reemplazado por un enlace simbólico, el… | |
| Modificada | Media (6.9) | 1.0% | — | MariadbRedhat Enterprise Linux | 12/6/2026 | 17/9/2026 | MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though… | |
| Aplazada | Crítica (9.9) | 1.4% | — | UID Enterprise AgentAI | 12/6/2026 | 17/6/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device. | |
| Analizada | Crítica (9.8) | 9.4% | ⚠ Explotación activa💥 Exploit | Oracle Peoplesoft Enterprise Peopletools | 11/6/2026 | 23/7/2026 | Vulnerabilidad en el producto PeopleSoft Enterprise PeopleTools de Oracle PeopleSoft (componente: Updates Environment Management). Las versiones compatibles afectadas son 8.61 y 8.62. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso a la red a través de HTTP comprometer… | |
| Modificada | Alta (7.5) | 0.99% | — | Js-cookie Javascript CookieRedhat 3scale API ManagementRedhat Ansible Automation PlatformRedhat Openshift AI+2 | 10/6/2026 | 9/9/2026 | JavaScript Cookie es una API de JavaScript para manejar cookies, del lado del cliente. Antes de la versión 3.0.7, la función auxiliar interna assign() de js-cookie copia propiedades con for...in + asignación simple. Cuando el objeto fuente es producido por JSON.parse, el miembro __proto__ del objeto JSON es una… | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Lenovo Accessories AND Display Manager FOR EnterpriseAI | 10/6/2026 | 17/6/2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Analizada | Alta (8.1) | 0.65% | — | Vmware Spring FOR Apache KafkaRedhat FuseRedhat Jboss Enterprise Application Platform Expansion Pack | 10/6/2026 | 5/8/2026 | JsonKafkaHeaderMapper y el obsoleto DefaultKafkaHeaderMapper comparaban los encabezados de tipo con paquetes de confianza utilizando una comprobación de prefijo, lo que significaba que confiar en cualquier paquete confiaba implícitamente en todos sus subpaquetes. Combinado con la deserialización de beans… | |
| Analizada | Alta (8.7) | 0.73% | — | Image-sizeRedhat DiscoveryRedhat GatekeeperRedhat Trusted Artifact Signer+1 | 9/6/2026 | 24/7/2026 | image-size 1.1.0 anterior a 1.2.1 y 2.0.0 anterior a 2.0.2 contienen una vulnerabilidad de denegación de servicio en la función findBox al procesar imágenes especialmente manipuladas con cajas de tamaño cero. Atacantes remotos pueden causar el bloqueo de la aplicación al suministrar archivos de imagen JXL, HEIF o JP2… | |
| Modificada | Media (4.9) | 0.29% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | Se encontró un fallo en 389 Directory Server. El plugin de almacenamiento de contraseñas PBKDF2-SHA256 no impone un límite superior en el recuento de iteraciones extraído de los hashes de contraseñas almacenados. Un atacante privilegiado que puede modificar el hash de la contraseña de un usuario puede causar un… | |
| Modificada | Media (6.5) | 0.28% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | Se encontró una vulnerabilidad en 389 Directory Server. El plugin de almacenamiento de contraseñas SMD5 realiza un subdesbordamiento de entero sin signo al calcular la longitud del salt a partir de un hash de contraseña manipulado de menos de 16 bytes, lo que provoca una lectura excesiva del búfer que bloquea el… |