Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.6) | 0.41% | — | UI Edgemax EdgeswitchAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device. | |
| Analizada | Alta (7.6) | 0.32% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Alta (7.2) | 0.14% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle General Ledger executes to compromise… | |
| Analizada | Alta (7.6) | 0.32% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle General Ledger | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Alta (7.6) | 0.34% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle General Ledger. While the… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Pendiente de análisis | Alta (7.3) | 0.17% | — | Dell AppsyncAIDell Metro NodeAIDell UCC EdgeAIDell VxrailAI+5 | 18/8/2026 | 20/8/2026 | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Edge22 Studios LTD GP PremiumAI | 18/8/2026 | 8/9/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5. | |
| Analizada | Alta (8.3) | 0.73% | — | Microsoft Edge Chromium | 14/8/2026 | 18/8/2026 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Alta (7.1) | 0.25% | — | Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions. | |
| Analizada | Media (5.4) | 0.41% | — | Microsoft Edge Chromium | 11/8/2026 | 17/8/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.3) | 0.15% | — | Siemens Solid Edge Se2025Siemens Solid Edge Se2026 | 11/8/2026 | 10/9/2026 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PSM files. This could allow an attacker to execute code in the context… | |
| Analizada | Alta (7.3) | 0.15% | — | Siemens Solid Edge Se2025Siemens Solid Edge Se2026 | 11/8/2026 | 10/9/2026 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context… | |
| Analizada | Alta (7.3) | 0.15% | — | Siemens Solid Edge Se2025Siemens Solid Edge Se2026 | 11/8/2026 | 10/9/2026 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context… | |
| Analizada | Alta (7.3) | 0.15% | — | Siemens Solid Edge Se2025Siemens Solid Edge Se2026 | 11/8/2026 | 10/9/2026 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute… | |
| Analizada | Alta (7.3) | 0.15% | — | Siemens Solid Edge Se2025Siemens Solid Edge Se2026 | 11/8/2026 | 10/9/2026 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute… | |
| Analizada | Alta (7.3) | 0.15% | — | Siemens Solid Edge Se2025Siemens Solid Edge Se2026 | 11/8/2026 | 10/9/2026 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context… | |
| Analizada | Alta (7.3) | 0.15% | — | Siemens Solid Edge Se2025Siemens Solid Edge Se2026 | 11/8/2026 | 10/9/2026 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context… | |
| Analizada | Crítica (9.1) | 0.93% | — | Microsoft Azure Confidential Ledger | 7/8/2026 | 7/8/2026 | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | |
| Aplazada | Alta (7.2) | 0.92% | — | FledgeAI | 5/8/2026 | 26/8/2026 | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the first extracted tar member's filename (tar_file_names[0]) and builds a shell command via string formatting. Because os.system invokes a shell and no quoting (shlex.quote, list-form subprocess) is… | |
| Aplazada | Media (4.9) | 0.43% | — | FledgeAI | 5/8/2026 | 26/8/2026 | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile.extractall(temp_path) on an admin-uploaded tar archive with no filter argument and no per-member path validation. Requires the admin role (@has_permission("admin")). | |
| Analizada | Alta (8.8) | 0.77% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.1) | 0.39% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |