Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

8468 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.58%—Gnome GlibRedhat OpenshiftRedhat Enterprise Linux11/12/20257/10/2026
Se encontró una falla en glib. Esta vulnerabilidad permite un desbordamiento de búfer de montón y denegación de servicio (DoS) a través de un desbordamiento de entero en la función escape_byte_string() de GIO (Entrada/Salida de GLib) de GLib al procesar valores de atributos de archivos maliciosos o de sistemas de…
ModificadaCrítica (9.8)0.83%—Gnome GlibRedhat Enterprise Linux10/12/20252/10/2026
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
AplazadaMedia (5.5)0.31%—SAP Enterprise Search FOR AbapAI9/12/20257/10/2026
Debido a una falta de verificación de autorización en SAP Enterprise Search para ABAP, un atacante con altos privilegios puede leer y exportar el contenido de tablas de base de datos a un informe ABAP. Esto podría llevar a un alto impacto en la confidencialidad de los datos y un bajo impacto en la integridad de los…
AplazadaMedia (6.1)0.26%—SAP Netweaver Enterprise PortalAI9/12/20257/10/2026
Debido a una vulnerabilidad de cross-site scripting (XSS) en SAP NetWeaver Enterprise Portal, un atacante no autenticado podría inyectar scripts maliciosos que se ejecutan en el contexto de los navegadores de otros usuarios, permitiendo al atacante robar cookies de sesión, tokens y otra información sensible. Como…
AnalizadaMedia (5.4)0.24%—Chinasystems Eximbills Enterprise1/12/202517/6/2026
Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the TMPL_INFO parameter is stored server-side and rendered to other users, enabling arbitrary JavaScript execution in their…
AnalizadaCrítica (9.8)0.57%—Ncp-e NCP Secure Entry ClientNcp-e Secure Enterprise Client26/11/202517/6/2026
NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.
ModificadaAlta (7.7)0.32%—Redhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little EndianRedhat Codeready Linux Builder FOR X86 64+2526/11/202531/8/2026
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow,…
AplazadaMedia (6.8)0.24%—Wickr GOVAIWickr EnterpriseAIAmazon WickrAI21/11/202517/6/2026
Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linux may allow a call participant to continue receiving audio input from another user after they close their call window. This issue occurs under certain conditions, which require the affected user to…
AnalizadaMedia (4.8)0.21%—Mieweb Enterprise Health20/11/202517/6/2026
Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 2025-03-14.
AnalizadaAlta (7.5)0.69%—Haproxy Aloha ApplianceHaproxyHaproxy EnterpriseHaproxy Kubernetes Ingress Controller19/11/202517/6/2026
Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
AnalizadaAlta (8.8)0.23%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+518/11/202517/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the SameSite=Lax cookie attribute is used as a mitigation, it is ineffective…
AplazadaAlta (8.6)0.74%—Ucancode E-xd++ Visualization Enterprise SuiteAI12/11/202517/6/2026
UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A crafted input may cause the control to…
AplazadaMedia (6.5)0.26%—SAP Netweaver Enterprise PortalAI11/11/202517/6/2026
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI lookup operations, enabling access to an unintended JNDI provider.�This could further lead to disclosure or modification of information about the server. There is no impact on…
AnalizadaAlta (8.6)0.65%—Github Enterprise Server10/11/202517/6/2026
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross-site scripting via Issues search label filter that could lead to privilege escalation and unauthorized workflow triggers. Successful exploitation requires an attacker to have access to the target…
AnalizadaAlta (7.5)0.66%—Github Enterprise Server10/11/20257/10/2026
Una vulnerabilidad de escalada de privilegios fue identificada en GitHub Enterprise Server que permitía a un administrador de Enterprise autenticado obtener acceso SSH de root al dispositivo explotando un escape de symlink en entornos de hooks de pre-recepción. Al crear un repositorio y entorno maliciosos, un atacante…
AnalizadaAlta (8.8)0.40%—Elastic Cloud Enterprise7/11/20257/10/2026
Autorización incorrecta en Elastic Cloud Enterprise puede conducir a Escalada de privilegios donde el usuario 'readonly' integrado puede llamar a APIs que no deberían estar permitidas. La lista de APIs que se ven afectadas por este problema es: post:/platform/configuration/security/service-accounts…
AnalizadaMedia (6.1)0.19%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+55/11/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, a malicious actor can inject arbitrary JavaScript into the response, leading to reflected XSS. Successful exploitation could result in…
AnalizadaAlta (7.2)0.47%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Micro Integrator+25/11/202517/6/2026
An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with elevated privileges can execute arbitrary code within the integration runtime environment. By default, access to these scripting…
AnalizadaAlta (7.2)0.60%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+55/11/202517/6/2026
An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious actor with administrative privileges can upload a specially crafted file to a user-controlled location within the deployment. Successful…
AnalizadaCrítica (9.1)0.46%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+45/11/202517/6/2026
An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external entities. A successful attack could enable a remote, unauthenticated attacker…
AnalizadaAlta (7.2)0.91%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+45/11/202517/6/2026
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with appropriate privileges can upload a malicious file to a user-controlled location on the server, potentially leading to remote code…
AnalizadaAlta (7.3)0.28%—X.org X ServerX.org XwaylandIBM ViosIBM AIX+730/10/20251/7/2026
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
AnalizadaAlta (7.3)0.30%—X.org X ServerX.org XwaylandIBM ViosIBM AIX+730/10/20251/7/2026
A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.
AnalizadaAlta (7.5)18%💥 ExploitRocketsoftware Trufusion Enterprise27/10/202517/6/2026
TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers.
AnalizadaCrítica (9.8)0.87%—Rocketsoftware Trufusion Enterprise27/10/202517/6/2026
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be used to write to any filename with any file type at any location…