Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
–

8556 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.9)0.43%—Oracle Webcenter Enterprise Capture17/6/202623/6/2026
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter…
AnalizadaCrítica (9.9)0.43%—Oracle Webcenter Enterprise Capture17/6/202623/6/2026
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter…
AnalizadaCrítica (9.9)0.43%—Oracle Webcenter Enterprise Capture17/6/202623/6/2026
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter…
AnalizadaCrítica (9.9)0.43%—Oracle Webcenter Enterprise Capture17/6/202623/6/2026
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter…
AnalizadaCrítica (9.9)0.43%—Oracle Webcenter Enterprise Capture17/6/202623/6/2026
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter…
AnalizadaAlta (8.1)0.39%—Oracle Peoplesoft Enterprise PT Peopletools17/6/202624/6/2026
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT…
AnalizadaCrítica (9.8)0.51%—Oracle Peoplesoft Enterprise PT Peopletools17/6/202624/6/2026
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT…
AnalizadaAlta (8.1)0.39%—Oracle Peoplesoft Enterprise PT Peopletools17/6/202624/6/2026
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Application Server). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT…
AnalizadaAlta (8.2)0.35%—Oracle Peoplesoft Enterprise PT Peopletools17/6/202624/6/2026
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT…
AnalizadaAlta (8.4)0.19%—Oracle Peoplesoft Enterprise PT Peopletools17/6/202624/6/2026
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PT PeopleTools…
AnalizadaAlta (8.7)0.34%—Oracle Peoplesoft Enterprise PT Peopletools17/6/202624/6/2026
Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. While…
AnalizadaAlta (8.1)0.25%—Gnome LocalsearchRedhat Enterprise Linux16/6/202617/6/2026
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the…
AnalizadaMedia (6.1)0.16%—Gnome LocalsearchRedhat Enterprise Linux16/6/202617/6/2026
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by…
AnalizadaMedia (5.6)0.21%—Gnome LocalsearchRedhat Enterprise Linux16/6/202618/6/2026
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a…
ModificadaMedia (5.5)0.19%—Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux13/6/202621/9/2026
Se encontró una vulnerabilidad de inyección de contenido en los scripts del gestor de eventos post-creación de ABRT en libreport. El script de evento consulta el registro de systemd en busca de entradas de registro que coincidan con el proceso bloqueado y escribe los resultados en archivos en el directorio de volcado…
ModificadaAlta (7.8)0.23%—Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux13/6/202621/9/2026
Una vulnerabilidad de seguimiento de enlaces simbólicos fue encontrada en los scripts del gestor de eventos post-creación de ABRT en libreport. Los scripts de eventos escriben archivos de salida usando redirecciones de shell sin la bandera O_NOFOLLOW. Si el archivo objetivo es reemplazado por un enlace simbólico, el…
ModificadaMedia (6.9)1.0%—MariadbRedhat Enterprise Linux12/6/202617/9/2026
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though…
AplazadaCrítica (9.9)1.4%—UID Enterprise AgentAI12/6/202617/6/2026
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.
AnalizadaCrítica (9.8)9.4%⚠ Explotación activa💥 ExploitOracle Peoplesoft Enterprise Peopletools11/6/202623/7/2026
Vulnerabilidad en el producto PeopleSoft Enterprise PeopleTools de Oracle PeopleSoft (componente: Updates Environment Management). Las versiones compatibles afectadas son 8.61 y 8.62. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso a la red a través de HTTP comprometer…
ModificadaAlta (7.5)0.99%—Js-cookie Javascript CookieRedhat 3scale API ManagementRedhat Ansible Automation PlatformRedhat Openshift AI+210/6/20269/9/2026
JavaScript Cookie es una API de JavaScript para manejar cookies, del lado del cliente. Antes de la versión 3.0.7, la función auxiliar interna assign() de js-cookie copia propiedades con for...in + asignación simple. Cuando el objeto fuente es producido por JSON.parse, el miembro __proto__ del objeto JSON es una…
Pendiente de análisisAlta (8.5)0.15%—Lenovo Accessories AND Display Manager FOR EnterpriseAI10/6/202617/6/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
AnalizadaAlta (8.1)0.65%—Vmware Spring FOR Apache KafkaRedhat FuseRedhat Jboss Enterprise Application Platform Expansion Pack10/6/20265/8/2026
JsonKafkaHeaderMapper y el obsoleto DefaultKafkaHeaderMapper comparaban los encabezados de tipo con paquetes de confianza utilizando una comprobación de prefijo, lo que significaba que confiar en cualquier paquete confiaba implícitamente en todos sus subpaquetes. Combinado con la deserialización de beans…
AnalizadaAlta (8.7)0.73%—Image-sizeRedhat DiscoveryRedhat GatekeeperRedhat Trusted Artifact Signer+19/6/202624/7/2026
image-size 1.1.0 anterior a 1.2.1 y 2.0.0 anterior a 2.0.2 contienen una vulnerabilidad de denegación de servicio en la función findBox al procesar imágenes especialmente manipuladas con cajas de tamaño cero. Atacantes remotos pueden causar el bloqueo de la aplicación al suministrar archivos de imagen JXL, HEIF o JP2…
ModificadaMedia (4.9)0.29%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202623/7/2026
Se encontró un fallo en 389 Directory Server. El plugin de almacenamiento de contraseñas PBKDF2-SHA256 no impone un límite superior en el recuento de iteraciones extraído de los hashes de contraseñas almacenados. Un atacante privilegiado que puede modificar el hash de la contraseña de un usuario puede causar un…
ModificadaMedia (6.5)0.28%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202623/7/2026
Se encontró una vulnerabilidad en 389 Directory Server. El plugin de almacenamiento de contraseñas SMD5 realiza un subdesbordamiento de entero sin signo al calcular la longitud del salt a partir de un hash de contraseña manipulado de menos de 16 bytes, lo que provoca una lectura excesiva del búfer que bloquea el…