Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3977 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.71% | — | SafelineAI | 16/9/2026 | 23/9/2026 | SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp can regenerate the secret and forge valid administrator session cookies to gain… | |
| Aplazada | Baja (1.9) | 0.38% | — | Sourcecodester Online Food Ordering SystemAI | 16/9/2026 | 22/9/2026 | A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Pendiente de análisis | Media (4.2) | 0.23% | — | Jenkins Pipeline Groovy LibrariesAIJenkins PipelineAI | 16/9/2026 | 18/9/2026 | Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the library, resulting in a path traversal… | |
| Pendiente de análisis | Baja (3.1) | 0.22% | — | Jenkins Pipeline Multibranch PluginAI | 16/9/2026 | 18/9/2026 | Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. | |
| Pendiente de análisis | Crítica (9.1) | 0.20% | — | Delinea Secret ServerAI | 15/9/2026 | 18/9/2026 | An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed. | |
| Pendiente de análisis | Alta (7.5) | 0.39% | — | Oracle Sales OfflineAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of… | |
| Pendiente de análisis | Alta (7.7) | 0.34% | — | Oracle Sales OfflineAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. While the… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Sales OnlineAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online. Successful attacks of… | |
| Aplazada | Alta (8.5) | 0.29% | — | Oracle Sales OnlineAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: OSO Other). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online. While the vulnerability is in… | |
| Aplazada | Alta (7.6) | 0.15% | — | Oracle Sales OnlineAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online. Successful attacks… | |
| Pendiente de análisis | Media (6.5) | 0.59% | — | Pipelines-as-codeAITektonAI | 15/9/2026 | 30/9/2026 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the repository that triggered the event when the App is installed across multiple… | |
| Pendiente de análisis | Alta (8.2) | 0.27% | — | Cd.foundation Pipelines AS CodeAI | 15/9/2026 | 30/9/2026 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Faculty Clearance SystemAI | 15/9/2026 | 17/9/2026 | A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture Upload. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Faculty Clearance SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Faculty Clearance SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injection. It is possible to launch the attack remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Faculty Clearance SystemAI | 15/9/2026 | 16/9/2026 | A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.52% | — | Subhajitkhan Online-clinic-management-systemAI | 15/9/2026 | 15/9/2026 | A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of the argument adminmail can lead to authorization bypass. The attack may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Katojkalemba Online Food Ordering SystemAI | 15/9/2026 | 15/9/2026 | A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Katojkalemba Online Food Ordering SystemAI | 15/9/2026 | 16/9/2026 | A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released… | |
| Aplazada | Media (5.5) | 0.43% | — | Subhajitkhan Online-clinic-management-systemAI | 14/9/2026 | 15/9/2026 | A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd can lead to sql injection. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Subhajitkhan Online-clinic-management-systemAI | 14/9/2026 | 14/9/2026 | A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of the argument searchtext results in sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 0.32% | — | Gongshengyue OnlinebooksAI | 13/9/2026 | 16/9/2026 | A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection. The attack may… | |
| Aplazada | Media (6.4) | 0.36% | — | Bold-themes Bold Timeline LiteAI | 11/9/2026 | 11/9/2026 | The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+4 | 8/9/2026 | 17/9/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+4 | 8/9/2026 | 17/9/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |