Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
–

8468 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.9)0.65%—Github Enterprise Server21/4/202617/6/2026
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through a timing side-channel attack against the notebook rendering service. When private mode was disabled, the notebook viewer followed…
AnalizadaAlta (7.2)0.48%—Github Enterprise Server21/4/202617/6/2026
An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended installation scope, which can include write operations, via an authorization fallback that treated a…
AnalizadaMedia (5.3)0.50%—Github Enterprise Server21/4/202617/6/2026
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API endpoint did not perform an early authorization check, and validation error messages included the…
AnalizadaAlta (7.5)0.74%—Github Enterprise Server21/4/202617/6/2026
An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker with knowledge of a first-party OAuth application's registered callback URL could craft a malicious authorization link that, when clicked by a victim,…
AnalizadaMedia (5.3)0.45%—Github Enterprise Server21/4/202617/6/2026
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list on another repository by manipulating the owner_id parameter in the request body. Authorization was…
AnalizadaMedia (5.7)0.32%—Oracle Peoplesoft Enterprise CS Student Records21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records.…
AnalizadaAlta (8.1)0.36%—Oracle Peoplesoft Enterprise Peopletools21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks…
AnalizadaMedia (5.4)0.21%—Oracle Peoplesoft Enterprise Peopletools21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks…
AnalizadaMedia (6.5)0.35%—Oracle Peoplesoft Enterprise FIN Project Costing21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Project Costing.…
AnalizadaMedia (6.5)0.35%—Oracle Peoplesoft Enterprise FIN Maintenance Management21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN…
AnalizadaMedia (6.5)0.39%—Oracle Peoplesoft Enterprise FIN Contracts21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Contracts. Successful attacks…
AnalizadaMedia (6.5)0.35%—Oracle Peoplesoft Enterprise FIN Maintenance Management21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN…
AnalizadaMedia (6.5)0.35%—Oracle Peoplesoft Enterprise SCM Purchasing21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful…
AnalizadaMedia (6.5)0.41%—Oracle Peoplesoft Enterprise HCM Human Resources21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Job Profile Manager). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human…
AnalizadaCrítica (9.1)0.49%—Oracle Enterprise Manager Base Platform21/4/202617/6/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager…
AnalizadaMedia (6.6)0.29%—Oracle Peoplesoft Enterprise Peopletools21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the…
AnalizadaMedia (6.1)0.24%—Oracle Peoplesoft Enterprise Peopletools21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks…
AnalizadaMedia (6.5)0.41%—Oracle Peoplesoft Enterprise Human Capital Management Absence Management21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Absence…
AnalizadaMedia (5.4)0.15%💥 PoCOracle Peoplesoft Enterprise HCM Shared Components21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared…
AnalizadaMedia (5.4)0.17%💥 PoCOracle Peoplesoft Enterprise HCM Human Resources21/4/202617/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapshot). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human…
AnalizadaMedia (5.1)0.26%—Fudosecurity Fudo Enterprise20/4/20267/10/2026
Fudo Enterprise en versiones desde la 5.5.0 hasta la 5.6.2 permite a usuarios con bajos privilegios acceder a ciertos recursos exclusivos de administrador a través de puntos finales de API indebidamente protegidos. Esto incluye información sensible como registros del sistema y partes de la configuración del sistema.…
AplazadaBaja (2.1)0.43%—Emqx EnterpriseAI19/4/202617/6/2026
A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the component Session Handling. The manipulation results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted…
Pendiente de análisisMedia (6.2)0.15%—Sparxsystems Enterprise ArchitectAI17/4/20267/10/2026
Vulnerabilidad de Credenciales Insuficientemente Protegidas en Sparx Systems Pty Ltd. Sparx Enterprise Architect. El cliente revela el secreto de cliente OAuth2 en texto plano. El cliente de escritorio decodifica el secreto y usa el secreto en texto plano para intercambiarlo por tokens de acceso e ID como parte del…
AnalizadaAlta (7.8)0.22%—Ocaml OpamDebian LinuxRedhat Enterprise Linux16/4/202615/7/2026
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
AnalizadaMedia (5.7)0.11%—Sparxsystems Enterprise Architect16/4/20267/10/2026
Credenciales insuficientemente protegidas en Sparx Systems Pty Ltd. Sparx Enterprise Architect. El cliente no verifica el receptor de las credenciales OAuth2 durante la autenticación OpenID