Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
8468 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.9) | 0.65% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through a timing side-channel attack against the notebook rendering service. When private mode was disabled, the notebook viewer followed… | |
| Analizada | Alta (7.2) | 0.48% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended installation scope, which can include write operations, via an authorization fallback that treated a… | |
| Analizada | Media (5.3) | 0.50% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API endpoint did not perform an early authorization check, and validation error messages included the… | |
| Analizada | Alta (7.5) | 0.74% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker with knowledge of a first-party OAuth application's registered callback URL could craft a malicious authorization link that, when clicked by a victim,… | |
| Analizada | Media (5.3) | 0.45% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list on another repository by manipulating the owner_id parameter in the request body. Authorization was… | |
| Analizada | Media (5.7) | 0.32% | — | Oracle Peoplesoft Enterprise CS Student Records | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records.… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Peoplesoft Enterprise Peopletools | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks… | |
| Analizada | Media (5.4) | 0.21% | — | Oracle Peoplesoft Enterprise Peopletools | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Peoplesoft Enterprise FIN Project Costing | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Project Costing.… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Peoplesoft Enterprise FIN Maintenance Management | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN… | |
| Analizada | Media (6.5) | 0.39% | — | Oracle Peoplesoft Enterprise FIN Contracts | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Contracts. Successful attacks… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Peoplesoft Enterprise FIN Maintenance Management | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Peoplesoft Enterprise SCM Purchasing | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful… | |
| Analizada | Media (6.5) | 0.41% | — | Oracle Peoplesoft Enterprise HCM Human Resources | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Job Profile Manager). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Enterprise Manager Base Platform | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Analizada | Media (6.6) | 0.29% | — | Oracle Peoplesoft Enterprise Peopletools | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Peoplesoft Enterprise Peopletools | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks… | |
| Analizada | Media (6.5) | 0.41% | — | Oracle Peoplesoft Enterprise Human Capital Management Absence Management | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Absence… | |
| Analizada | Media (5.4) | 0.15% | 💥 PoC | Oracle Peoplesoft Enterprise HCM Shared Components | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared… | |
| Analizada | Media (5.4) | 0.17% | 💥 PoC | Oracle Peoplesoft Enterprise HCM Human Resources | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapshot). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Analizada | Media (5.1) | 0.26% | — | Fudosecurity Fudo Enterprise | 20/4/2026 | 7/10/2026 | Fudo Enterprise en versiones desde la 5.5.0 hasta la 5.6.2 permite a usuarios con bajos privilegios acceder a ciertos recursos exclusivos de administrador a través de puntos finales de API indebidamente protegidos. Esto incluye información sensible como registros del sistema y partes de la configuración del sistema.… | |
| Aplazada | Baja (2.1) | 0.43% | — | Emqx EnterpriseAI | 19/4/2026 | 17/6/2026 | A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the component Session Handling. The manipulation results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted… | |
| Pendiente de análisis | Media (6.2) | 0.15% | — | Sparxsystems Enterprise ArchitectAI | 17/4/2026 | 7/10/2026 | Vulnerabilidad de Credenciales Insuficientemente Protegidas en Sparx Systems Pty Ltd. Sparx Enterprise Architect. El cliente revela el secreto de cliente OAuth2 en texto plano. El cliente de escritorio decodifica el secreto y usa el secreto en texto plano para intercambiarlo por tokens de acceso e ID como parte del… | |
| Analizada | Alta (7.8) | 0.22% | — | Ocaml OpamDebian LinuxRedhat Enterprise Linux | 16/4/2026 | 15/7/2026 | In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. | |
| Analizada | Media (5.7) | 0.11% | — | Sparxsystems Enterprise Architect | 16/4/2026 | 7/10/2026 | Credenciales insuficientemente protegidas en Sparx Systems Pty Ltd. Sparx Enterprise Architect. El cliente no verifica el receptor de las credenciales OAuth2 durante la autenticación OpenID |