Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.43% | — | Oracle Peoplesoft Enterprise Peopletools | 18/8/2026 | 21/8/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Configuration Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Alta (7.2) | 0.14% | — | Oracle Peoplesoft Enterprise Peopletools | 18/8/2026 | 21/8/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Data Mover). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Peoplesoft Enterprise Peopletools | 18/8/2026 | 21/8/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Install and Packaging). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Peoplesoft Enterprise Peopletools | 18/8/2026 | 21/8/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Peoplesoft Enterprise Peopletools | 18/8/2026 | 21/8/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Peoplesoft Enterprise Peopletools | 18/8/2026 | 21/8/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Aplazada | Baja (2.1) | 0.45% | — | Alaev SEO Tools ExtensionAI | 17/8/2026 | 20/8/2026 | A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the function addDiv of the file src/popup.html of the component Popup UI. Performing a manipulation results in basic cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. The… | |
| Pendiente de análisis | Alta (8.8) | 0.44% | — | SAP Abap Development ToolsAISAP Netweaver AS AbapAI | 11/8/2026 | 26/8/2026 | SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and… | |
| Pendiente de análisis | Alta (8.6) | 0.52% | — | Amazon Strands Agents ToolsAI | 6/8/2026 | 12/8/2026 | Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace… | |
| Analizada | Crítica (9.1) | 0.24% | — | Dell Rvtools | 6/8/2026 | 10/8/2026 | Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity. | |
| Aplazada | Media (6.5) | 0.44% | — | Udimi ToolsAI | 5/8/2026 | 12/8/2026 | The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` function in all versions up to, and including, 3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's six… | |
| Analizada | Media (4.6) | 0.23% | — | Eclipse Accessibility Tools FrameworkSoumu Michecker | 5/8/2026 | 10/8/2026 | In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this vulnerability is exploited, a malicious third party… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | Amazon Strands Agents ToolsAI | 3/8/2026 | 4/8/2026 | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue,… | |
| Pendiente de análisis | Media (6.9) | 0.52% | — | Strands Agents ToolsAI | 31/7/2026 | 4/8/2026 | Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to… | |
| Analizada | Baja (3.3) | 0.14% | — | Broadcom Spring Tools | 30/7/2026 | 8/9/2026 | The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form… | |
| Analizada | Alta (8) | 0.33% | — | Broadcom Spring Tools | 30/7/2026 | 8/9/2026 | Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier | |
| Analizada | Media (5.4) | 0.17% | — | Broadcom Spring Tools | 30/7/2026 | 30/9/2026 | Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a… | |
| Analizada | Media (4.4) | 0.10% | — | Broadcom Spring Tools | 30/7/2026 | 30/9/2026 | Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes as cleartext XML, either to workspace metadata or, if the user marks the… | |
| Analizada | Alta (8.3) | 0.24% | — | Broadcom Spring Tools | 30/7/2026 | 30/9/2026 | When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a… | |
| Analizada | Alta (8) | 0.29% | — | Broadcom Spring Tools | 30/7/2026 | 30/9/2026 | The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier | |
| Analizada | Baja (3.7) | 0.23% | — | Oracle JD Edwards Enterpriseone Tools | 21/7/2026 | 6/8/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle JD Edwards Enterpriseone Tools | 21/7/2026 | 5/8/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the… | |
| Analizada | Media (6) | 0.16% | — | Oracle JD Edwards Enterpriseone Tools | 21/7/2026 | 5/8/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle JD Edwards Enterpriseone Tools | 21/7/2026 | 5/8/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.… | |
| Analizada | Baja (3.6) | 0.11% | — | Oracle JD Edwards Enterpriseone Tools | 21/7/2026 | 6/8/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools… |