Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 299 respecto a la semana anterior
Críticas / altas1298▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
8556 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.22% | — | Redhat InstructlabRedhat Enterprise Linux AI | 22/4/2026 | 17/6/2026 | A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data… | |
| Modificada | Alta (7.8) | 0.20% | — | GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the… | |
| Modificada | Media (5) | 0.14% | — | GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming… | |
| Analizada | Media (5.5) | 0.15% | — | GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The… | |
| Analizada | Media (5.5) | 0.15% | — | GNU NanoRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Alta (8.9) | 0.65% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through a timing side-channel attack against the notebook rendering service. When private mode was disabled, the notebook viewer followed… | |
| Analizada | Alta (7.2) | 0.48% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended installation scope, which can include write operations, via an authorization fallback that treated a… | |
| Analizada | Media (5.3) | 0.50% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API endpoint did not perform an early authorization check, and validation error messages included the… | |
| Analizada | Alta (7.5) | 0.74% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker with knowledge of a first-party OAuth application's registered callback URL could craft a malicious authorization link that, when clicked by a victim,… | |
| Analizada | Media (5.3) | 0.45% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list on another repository by manipulating the owner_id parameter in the request body. Authorization was… | |
| Analizada | Media (5.7) | 0.32% | — | Oracle Peoplesoft Enterprise CS Student Records | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records.… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Peoplesoft Enterprise Peopletools | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks… | |
| Analizada | Media (5.4) | 0.21% | — | Oracle Peoplesoft Enterprise Peopletools | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Peoplesoft Enterprise FIN Project Costing | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Project Costing.… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Peoplesoft Enterprise FIN Maintenance Management | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN… | |
| Analizada | Media (6.5) | 0.39% | — | Oracle Peoplesoft Enterprise FIN Contracts | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Contracts. Successful attacks… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Peoplesoft Enterprise FIN Maintenance Management | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Peoplesoft Enterprise SCM Purchasing | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful… | |
| Analizada | Media (6.5) | 0.41% | — | Oracle Peoplesoft Enterprise HCM Human Resources | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Job Profile Manager). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Enterprise Manager Base Platform | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Analizada | Media (6.6) | 0.29% | — | Oracle Peoplesoft Enterprise Peopletools | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Peoplesoft Enterprise Peopletools | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks… | |
| Analizada | Media (6.5) | 0.41% | — | Oracle Peoplesoft Enterprise Human Capital Management Absence Management | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Absence… | |
| Analizada | Media (5.4) | 0.15% | 💥 PoC | Oracle Peoplesoft Enterprise HCM Shared Components | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared… |