Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

2803 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisCrítica (9.1)0.35%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.
En análisisMedia (5.3)0.13%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 through 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064 IBM Financial Transaction Manager transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by…
En análisisAlta (7.3)0.22%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
Pendiente de análisisMedia (6.1)0.20%—IBM Financial Transaction Manager FOR Swift Services FOR MultiplatformsAI18/9/202622/9/2026
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…
AplazadaMedia (6.1)0.37%—Qodeinteractive QI Addons FOR ElementorAI18/9/202619/9/2026
The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaMedia (4.3)0.14%—Active Woot Products Tables FOR WoocommerceAI17/9/202618/9/2026
The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products.
Pendiente de análisisAlta (8)0.52%—Noelware Docker-manifest-actionAIQuay Builder-qemuAI16/9/202618/9/2026
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials…
AplazadaAlta (7.7)0.34%—Oracle Customer Interaction HistoryAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Interaction…
AplazadaAlta (8.8)0.42%—Oracle E-business SuiteAIOracle Customer Interaction HistoryAI15/9/202617/9/2026
Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Customer Interaction…
AplazadaAlta (8.8)0.42%—Oracle E-business SuiteAIOracle Customer Interaction HistoryAI15/9/202617/9/2026
Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Interaction…
Pendiente de análisisAlta (7.7)0.34%—Oracle Peoplesoft Enterprise Prtl Interaction HUBAI15/9/202616/9/2026
Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: Enterprise Portal). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction…
AplazadaAlta (7.1)0.53%—Github ActionsAI15/9/202630/9/2026
githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly into the Bash assignment for ISSUE_TITLE before shell parsing. An issue title containing shell…
Pendiente de análisisAlta (7.1)0.42%—ActivitiAI14/9/202624/9/2026
Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task uses variable-backed body fields,…
AplazadaBaja (3.5)0.26%—SEP SesamAIMicrosoft Active DirectoryAI12/9/202622/9/2026
SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, which may allow multiple SEP sesam user accounts to be created for…
Pendiente de análisisAlta (7.7)0.38%—Gemini CLIAIGemini CLI Github ActionAI10/9/202623/9/2026
A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env files overriding GEMINI_CLI_HOME to load malicious configuration files and bypass…
AplazadaCrítica (9.8)0.69%—Actions Semiconductor CO LTD Tool - Media Player UtilitiesAI9/9/202610/9/2026
An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components
Pendiente de análisisMedia (6.8)0.14%—Activecampaign GeneralAI9/9/202614/9/2026
A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An…
AnalizadaAlta (7.5)0.62%—Apache ActivemqApache Activemq ALLApache Activemq Broker9/9/202618/9/2026
Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All:…
AplazadaAlta (8)0.41%—Qodeinteractive OptimizeAI5/9/20268/9/2026
The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a…
AplazadaBaja (2.7)0.26%—Qodeinteractive OptimizeAI5/9/20268/9/2026
The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names…
Pendiente de análisisCrítica (10)0.81%—Microsoft Azure Active Directory B2CAI3/9/20268/9/2026
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
AnalizadaMedia (5.3)0.33%—Miniorange Ldap / Active Directory Integration2/9/202616/9/2026
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.
AplazadaAlta (7.1)0.13%—Activity LOGAI2/9/20263/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
AplazadaAlta (7.1)0.25%—Interactive GEO MapsAI2/9/20262/9/2026
Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
Pendiente de análisisAlta (8.5)0.11%—Rockwellautomation Factorytalk Activation ManagerAI1/9/20261/9/2026
A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack…
Orbitaley — Vulnerabilidades