Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
3708 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.16% | — | Colorful IgamecenterAIWinring0x64AI | 31/8/2026 | 31/8/2026 | A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper privilege management. Attacking locally is a… | |
| Aplazada | Crítica (9.8) | 0.28% | — | UIX UsercenterAI | 29/8/2026 | 31/8/2026 | The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated… | |
| Pendiente de análisis | Alta (7.7) | 0.10% | — | Cloudfoundry Bosh DirectorAIVmware VcenterAI | 29/8/2026 | 3/9/2026 | Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic… | |
| Aplazada | Crítica (9.3) | 0.52% | — | Datiphy Data Management CenterAI | 21/8/2026 | 26/8/2026 | External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences. | |
| Aplazada | Alta (8.8) | 0.73% | — | Datiphy Data Management CenterAI | 21/8/2026 | 26/8/2026 | Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory. | |
| Aplazada | Crítica (9.4) | 1.1% | — | Datiphy Data Management CenterAI | 21/8/2026 | 26/8/2026 | OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root. | |
| Aplazada | Crítica (9.3) | 0.49% | — | Datiphy Data Management CenterAI | 21/8/2026 | 26/8/2026 | Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials. | |
| Analizada | Alta (8.6) | 0.97% | — | Microsoft Partner Center | 20/8/2026 | 25/8/2026 | Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Cisco Unified Intelligence CenterAI | 19/8/2026 | 20/8/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this… | |
| Pendiente de análisis | Media (5) | 0.44% | — | Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI | 19/8/2026 | 20/8/2026 | A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. | |
| Pendiente de análisis | Alta (8.8) | 0.46% | — | Atlassian Crowd Data CenterAI | 18/8/2026 | 26/8/2026 | This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center. This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as… | |
| Pendiente de análisis | Crítica (9.3) | 0.51% | — | Atlassian Confluence Data CenterAIAtlassian Confluence ServerAI | 18/8/2026 | 26/8/2026 | This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS,… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Portal | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Alta (7.1) | 0.24% | — | Oracle Webcenter Content | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (8.2) | 0.32% | — | Oracle Email Center | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Component). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks… | |
| Analizada | Alta (7.1) | 0.18% | — | Oracle Webcenter Content | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Content executes to… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Webcenter Content | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to… | |
| Analizada | Alta (7.1) | 0.28% | — | Oracle Webcenter Content | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (7.1) | 0.32% | — | Oracle Webcenter Content | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Webcenter Portal | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Webcenter Portal | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Webcenter Portal | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Webcenter Portal | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful… | |
| Analizada | Alta (8.2) | 0.32% | — | Oracle Webcenter Portal | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Alta (8.7) | 0.33% | — | Oracle Webcenter Portal | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful… |