Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.31% | — | Oracle Work IN Process | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful… | |
| Analizada | Alta (7.6) | 0.15% | — | Oracle Work IN Process | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Work IN Process | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process. Successful… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Business Process Management Suite | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle… | |
| Aplazada | Alta (8.5) | 0.16% | — | Siemens ComosAISiemens Designcenter NXAISiemens Simcenter 3DAISiemens Simcenter FemapAI+6 | 14/7/2026 | 5/10/2026 | A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter… | |
| Aplazada | Alta (8.2) | 0.22% | — | Pontedilana Php-weasyprintAIKnplabs SnappyAISymfony ProcessAI | 19/6/2026 | 22/6/2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the shell command for WeasyPrint by passing the binary path through `escapeshellarg()` first and then checking the *quoted* result with `is_executable()`. On POSIX… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Process Manufacturing Process Planning | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Process Manufacturing Process Planning product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Process Manufacturing Product Development | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Process Manufacturing Product Development | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Pendiente de análisis | Media (4) | 0.13% | — | AMD Secure ProcessorAIAMD IommuAI | 9/6/2026 | 23/7/2026 | Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD Secure Processor (ASP), potentially resulting in loss of integrity. | |
| Aplazada | Crítica (9.3) | 0.42% | — | Sysinternals Process MonitorAI | 9/6/2026 | 23/7/2026 | A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker with low privileges to inject malicious JavaScript code into the application. This enables attackers to steal administrative access tokens and session credentials. | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | AMD Secure ProcessorAI | 1/6/2026 | 22/7/2026 | Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures leading to a potential escalation of privileges. | |
| Pendiente de análisis | Alta (8.7) | 0.35% | — | 3DS Delmia Service Process EngineerAI | 1/6/2026 | 22/7/2026 | A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Student Transcript Processing SystemAI | 26/5/2026 | 23/7/2026 | A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Student Transcript Processing SystemAI | 26/5/2026 | 23/7/2026 | A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the argument studentId/cid can lead to sql injection. The attack can be launched remotely. The exploit has been published and… | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Student Transcript Processing SystemAI | 26/5/2026 | 23/7/2026 | A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/student/index.php?view=view. Performing a manipulation of the argument studentId results in sql injection. The attack can be initiated remotely. The exploit is now public and… | |
| Aplazada | Media (6.9) | 0.78% | — | ProcessmakerAI | 16/5/2026 | 17/6/2026 | ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. Attackers can send requests with directory traversal sequences to access sensitive system files like /etc/passwd without authentication. | |
| Pendiente de análisis | Media (4.6) | 0.11% | — | AMD Secure ProcessorAI | 15/5/2026 | 17/6/2026 | Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FW SR-IOV command to cause out-of-bounds read, potentially resulting in SOC Driver memory contents exposure or an exception | |
| Pendiente de análisis | Media (5.3) | 0.21% | — | AMD Secure ProcessorAI | 15/5/2026 | 17/6/2026 | Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an input value to a function without sufficient privileges and successfully write data, potentially resulting in loss of integrity of availability. | |
| Pendiente de análisis | Alta (8.8) | 0.10% | — | AMD Secure ProcessorAI | 15/5/2026 | 17/6/2026 | Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution. | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | AMD Secure ProcessorAIAMD Video Core NextAI | 15/5/2026 | 17/6/2026 | Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure Processor (ASP) could allow an attacker with the ability to write outside the trusted memory range (TMR) to change the execution flow of the Video Core Next (VCN) firmware potentially impacting… | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | AMD Secure Processor PCI DriverAI | 15/5/2026 | 17/6/2026 | Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, potentially resulting in a loss of platform integrity or crash. | |
| Pendiente de análisis | Media (6.9) | 0.11% | — | AMD Secure Processor PCI DriverAI | 15/5/2026 | 17/6/2026 | Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in a crash or denial of service | |
| Analizada | Media (4.3) | 0.28% | — | Linuxfoundation Backstage/plugin-catalog-backend-module-unprocessedLinuxfoundation Backstage/plugin-catalog-unprocessed-entitiesLinuxfoundation Backstage/plugin-catalog-unprocessed-entities-common | 14/5/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is… | |
| Pendiente de análisis | Alta (8.5) | 0.13% | — | AMD Secure ProcessorAIAMD SEV SNPAI | 13/5/2026 | 17/6/2026 | Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access, potentially resulting in arbitrary code execution in AMD Secure Processor (ASP) and loss of the SEV-SNP guest's confidentiality and integrity. |