Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2814▼ 267 respecto a la semana anterior
Críticas / altas1316▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
14.266 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.55% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference. | |
| Analizada | Crítica (9.9) | 0.79% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (8.8) | 0.41% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow. | |
| Analizada | Alta (7.5) | 0.55% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. | |
| Analizada | Alta (7.8) | 0.14% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management. | |
| Analizada | Alta (7.5) | 0.55% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption. | |
| Analizada | Alta (8.2) | 0.50% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to access NFS-exported filesystems due to improper authentication. | |
| Analizada | Crítica (9.8) | 0.72% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication. | |
| Analizada | Alta (8.1) | 0.32% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized access to AIX systems due to improper validation of TLS certificates. | |
| Analizada | Crítica (9.9) | 1.1% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Crítica (9.1) | 0.63% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file. | |
| Analizada | Alta (8.2) | 0.59% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote attacker to overwrite files due to path traversal. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM ViosIBM AIX | 19/8/2026 | 20/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing during client registration due to buffer overflow. | |
| Aplazada | Alta (7.1) | 0.40% | — | Circl AIL FrameworkAI | 19/8/2026 | 26/8/2026 | AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can submit an arbitrary URL for crawling without adequate validation of the destination host. The crawler can therefore be… | |
| Aplazada | Alta (8.7) | 0.45% | — | AcmailerAI | 19/8/2026 | 28/8/2026 | An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. | |
| Aplazada | Media (5.1) | 0.26% | — | AcmailerAI | 19/8/2026 | 28/8/2026 | A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script. | |
| Aplazada | Media (6.4) | 0.37% | — | Confidential Containers Guest ComponentsAIImage-rs Image RSAI | 18/8/2026 | 9/9/2026 | Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafted OCI image layer can make image_rs::stream::unpack::unpack() create a hardlink outside its destination directory. In image-rs/src/stream/unpack.rs,… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Complex Maintenance Repair AND Overhaul | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Call Center Technology.… | |
| Analizada | Media (4.8) | 0.22% | — | Agile Engineering Data Management Product OF Oracle Supply Chain | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile… | |
| Analizada | Alta (8.2) | 0.29% | — | Agile Engineering Data Management Product OF Oracle Supply Chain | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile… | |
| Analizada | Alta (8.2) | 0.32% | — | Oracle Email Center | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Component). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks… | |
| Analizada | Alta (7.1) | 0.29% | — | Oracle Complex Maintenance Repair AND Overhaul | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Aplazada | Media (6.9) | 0.41% | — | PlainpadAILaravelAI | 18/8/2026 | 16/9/2026 | Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.php that is never instantiated under the Laravel 11+ skeleton, leaving the API… | |
| Pendiente de análisis | Alta (7.3) | 0.17% | — | Dell AppsyncAIDell Metro NodeAIDell UCC EdgeAIDell VxrailAI+5 | 18/8/2026 | 20/8/2026 | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4… | |
| Aplazada | Media (6.9) | 0.53% | — | AiosmtplibAI | 18/8/2026 | 18/9/2026 | aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is framed as additional standalone SMTP command lines, allowing an attacker who… |