Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
3708 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Enterprise Capture | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Alta (8.5) | 0.30% | — | Oracle Webcenter Enterprise Capture | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Webcenter Enterprise Capture | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Enterprise Capture | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter… | |
| Analizada | Alta (7.2) | 0.12% | — | Oracle Webcenter Enterprise Capture | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter… | |
| Analizada | Alta (8.5) | 0.30% | — | Oracle Webcenter Enterprise Capture | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Portal | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Portal | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful… | |
| Analizada | Crítica (9.3) | 0.38% | — | Oracle Webcenter Portal | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Portal | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Portal | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Webcenter Portal | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Webcenter Portal | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Portal | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Portal | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Atlassian Confluence Data CenterAI | 15/9/2026 | 16/9/2026 | This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be… | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Atlassian Jira Service Management Data CenterAI | 15/9/2026 | 17/9/2026 | This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. * Jira Service Management Data Center 11.3: Upgrade to a release greater than or equal to 11.3.11 | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Atlassian Confluence Data CenterAI | 15/9/2026 | 17/9/2026 | This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain… | |
| Pendiente de análisis | Alta (8.6) | 0.69% | — | TeamAIAmazon IAM Identity CenterAI | 14/9/2026 | 14/9/2026 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated… | |
| Aplazada | Alta (8.6) | 0.60% | — | Behavioral Technology Group PavlokAIApple Notification Center ServiceAI | 10/9/2026 | 10/9/2026 | A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local… | |
| Aplazada | Alta (8.5) | 0.38% | — | Siemens TeamcenterAI | 8/9/2026 | 9/9/2026 | A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute… | |
| Aplazada | Alta (7.7) | 0.20% | — | Asus Control Center Express AgentAI | 8/9/2026 | 28/9/2026 | Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the ' Security Update for ASUS Control Center Express Agent ' section on the ASUS… | |
| Aplazada | Crítica (10) | 0.34% | — | Asus Control CenterAI | 4/9/2026 | 17/9/2026 | Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode… | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Jenkins Update-center2AI | 2/9/2026 | 3/9/2026 | Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. | |
| Aplazada | Alta (8.5) | 0.18% | — | MSI Dragon CenterAIMSI Ntiolib X64AI | 31/8/2026 | 1/9/2026 | A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer overflow. The attack requires a local… |