Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
4214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.4) | 0.20% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Websphere Application ServerAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this… | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL… | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 14/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this… | |
| Pendiente de análisis | Media (4.4) | 0.15% | — | Citrix Workspace APP FOR WindowsAI | 11/9/2026 | 16/9/2026 | Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. | |
| Pendiente de análisis | Media (4.8) | 0.14% | — | Citrix Workspace APP FOR WindowsAI | 11/9/2026 | 16/9/2026 | Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. | |
| En análisis | Alta (8.8) | 0.15% | — | IBM Aspera Enterprise WebappsAI | 10/9/2026 | 11/9/2026 | IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container. | |
| Analizada | Media (5.3) | 0.43% | — | IBM Websphere Application Server | 10/9/2026 | 15/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints. | |
| Analizada | Alta (8.1) | 0.37% | — | IBM Websphere Application Server | 10/9/2026 | 15/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service. | |
| Analizada | Alta (7.1) | 0.16% | — | IBM Websphere Application Server | 10/9/2026 | 15/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources. | |
| Analizada | Media (5.3) | 0.49% | — | IBM Websphere Application Server | 10/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially leading to reduced availability of the affected service. | |
| Analizada | Alta (7.5) | 0.77% | — | IBM Websphere Application Server | 10/9/2026 | 16/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space. | |
| Aplazada | Alta (8.8) | 0.20% | — | Simply Schedule AppointmentsAI | 2/9/2026 | 4/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. | |
| Aplazada | Baja (1.9) | 0.21% | — | Airasia Move APPAI | 2/9/2026 | 2/9/2026 | A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument _display_name results in path traversal. The attack requires a local approach. The… | |
| Pendiente de análisis | Baja (2.3) | 0.25% | — | Netapp StoragegridAI | 28/8/2026 | 1/9/2026 | StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are susceptible to a Denial of Service vulnerability. Successful exploit could allow an attacker with some control over the environment to cause a partial Denial of Service. | |
| Aplazada | Crítica (9.1) | 0.44% | — | Plone.app.portletsAI | 28/8/2026 | 9/9/2026 | plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portlets/rss.py to download and retain excessive data in memory and deny… | |
| Aplazada | Alta (8.6) | 0.36% | — | Mobile APP FOR WoocommerceAI | 27/8/2026 | 28/8/2026 | Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. | |
| Aplazada | Media (4.3) | 0.15% | — | Shopapper Mobile APP BuilderAI | 27/8/2026 | 28/8/2026 | The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock… | |
| Aplazada | Crítica (10) | 0.60% | — | Miniorange Saml SSOAIMiniorange Saml SP Single Sign ON Login With AdfsAIMiniorange Saml SP Single Sign ON Saml SSO Login With Google AppsAIJoomlaAI | 25/8/2026 | 8/9/2026 | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the mo_saml_validate_signature() function performing a… | |
| Aplazada | Alta (8.7) | 0.90% | — | Craterapp CraterAI | 25/8/2026 | 24/9/2026 | Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequences to the unzip endpoint. Attackers can exploit unsanitized ZIP entry… | |
| Aplazada | Alta (8.6) | 0.53% | — | Woocommerce File ApprovalAI | 24/8/2026 | 24/8/2026 | Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Mobile Application Server | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application… | |
| Aplazada | Crítica (9.3) | 0.40% | — | JetappointmentAI | 18/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | |
| Pendiente de análisis | Media (5.2) | 0.18% | — | Citrix Workspace APPAI | 18/8/2026 | 28/8/2026 | External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607. |