Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

3834 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.41%—FlowintelAI27/8/202628/8/2026
Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This means that if an attacker already possesses a valid session—for example, from prior access or a stolen session token—the victim changing their password does not terminate that attacker’s access. The…
AplazadaMedia (5.1)0.39%—FlowintelAI27/8/202628/8/2026
Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as: Those values were concatenated directly into HTML strings before rendering. The upstream commit explicitly states that DOMPurify removed XSS vectors but still allowed other HTML elements, such as forms,…
AplazadaMedia (5.3)0.47%—FlowintelAI27/8/202628/8/2026
Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint accepts a user_id parameter identifying the user whose assignments should be returned, but previously had no role restriction beyond general API authentication. As a result, a lower-privileged…
AplazadaAlta (8.6)0.39%—FlowintelAI27/8/202628/8/2026
Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authorization check correctly prevented an organization administrator from editing users in another organization, but it did not prevent them from editing a full administrator within their own organization.…
AplazadaAlta (7.2)0.35%—FlowintelAI27/8/202628/8/2026
Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints. The routes generally received both a case identifier and a task identifier, but previously they did not enforce that the task actually belonged to the supplied case. As a…
AplazadaBaja (3.1)0.18%—HCL Intelliops Event ManagementAI27/8/202628/8/2026
HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session deletion.
AplazadaMedia (6.4)0.19%—HCL Intelliops Event ManagementAI27/8/202628/8/2026
HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of user sessions, resulting in sessions not being fully terminated after logout or deletion.
AplazadaMedia (5.1)0.40%—FlowintelAI27/8/202628/8/2026
Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case titles, a user able to create or modify a case title could store HTML or script-capable content that is later interpreted by the browser when another user views the calendar. The fix changes:…
AplazadaMedia (5.1)0.55%—FlowintelAI27/8/202628/8/2026
Affected versions of Flowintel render Mermaid blocks contained in stored case notes without sufficiently neutralizing attacker-controlled markup. Because Mermaid note content is persisted and later rendered for other users, an attacker with permission to create or edit a note could store a crafted Mermaid payload that…
AplazadaAlta (7.5)0.42%—FlowintelAI27/8/202628/8/2026
Affected versions of Flowintel allow the LOG_FILE configuration value to be modified through system settings without restricting it to a filename inside the intended log directory. Because the application constructs the log destination from this configurable value, an administrator could set LOG_FILE to an arbitrary…
AplazadaAlta (8.6)0.53%—FlowintelAI27/8/202628/8/2026
Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. While configuration values were normalized to Python literals, the corresponding keys were used directly when constructing and replacing lines in conf/config_module.py. The vulnerable code used…
AplazadaAlta (7.1)0.45%—FlowintelAIPandocAIXelatexAI27/8/202628/8/2026
Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.
AplazadaMedia (4.8)0.24%—HCL Intelliops Event ManagementAI20/8/202628/8/2026
HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation.
AplazadaMedia (5)0.28%—HCL Intelliops Event ManagementAI20/8/202629/9/2026
HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.
AplazadaMedia (5.9)0.23%—HCL Intelliops Event ManagementAI20/8/202629/9/2026
HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior.
AplazadaMedia (6.6)0.26%—HCL Intelliops Event ManagementAI20/8/202629/9/2026
HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.
AplazadaMedia (5.4)0.25%—HCL Intelliops Event ManagementAI20/8/202629/9/2026
HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.
AnalizadaMedia (5.3)0.39%—Cisco Talos Intelligence FOR Enterprise Security Cloud19/8/202621/8/2026
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and…
AnalizadaAlta (8.8)0.42%—Cisco Talos Intelligence FOR Enterprise Security Cloud19/8/202621/8/2026
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the instance to make an outbound request to…
Pendiente de análisisMedia (6.5)0.35%—Cisco Unified Intelligence CenterAI19/8/202620/8/2026
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this…
AnalizadaAlta (8)0.38%—Oracle Business Intelligence18/8/202624/8/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business…
AnalizadaAlta (7.5)0.41%—Oracle Business Intelligence18/8/202624/8/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business…
AnalizadaAlta (7.2)0.49%—Oracle Business Intelligence18/8/202624/8/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Answers). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business…
AnalizadaAlta (7)0.13%—Oracle Business Intelligence18/8/202624/8/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence…
AnalizadaAlta (7.8)0.16%—Oracle Business Intelligence18/8/202624/8/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence…