Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

1962 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.39%—Oracle Business Intelligence Enterprise EditionAI15/9/202621/9/2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
Pendiente de análisisAlta (8.5)0.23%—RenovateAIMend Renovate CEAIMend Renovate EEAIMend Renovate Enterprise EditionAI10/9/202629/9/2026
Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0), the manager/gradle-wrapper module does not escape the distributionUrl value read from a repository's…
Pendiente de análisisMedia (6.9)0.30%—RenovateAIMend Renovate CEAIMend Renovate Enterprise EditionAI10/9/202629/9/2026
Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updates are not subject to the internal `minimumReleaseAge` (stability age) checks.…
Pendiente de análisisAlta (8.3)0.39%—RenovateAIMend RenovateAIMend Renovate Enterprise EditionAI10/9/202629/9/2026
Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for Mutual TLS was incomplete. While the value of hostRules[].httpsPrivateKey was…
Pendiente de análisisCrítica (9.2)0.41%—RenovateAIMend Renovate CEAIMend Renovate EEAIMend Renovate Enterprise EditionAI10/9/202629/9/2026
Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the…
Pendiente de análisisCrítica (9.2)0.41%—RenovateAIMend Renovate CEAIMend Renovate Enterprise EditionAI10/9/202629/9/2026
Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials configured for that host to the URL given as the 'next' page. Because the pagination URL…
AplazadaAlta (8.5)0.43%—BurgereditorAI10/9/20261/10/2026
BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allowing arbitrary PHP code to be executed.
AplazadaMedia (5.3)0.30%—BurgereditorAI10/9/20261/10/2026
BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product.
AplazadaMedia (6.1)0.25%—Silverpeas CoreAICkeditorAI8/9/20269/9/2026
Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.
AnalizadaAlta (8.3)0.32%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
AnalizadaMedia (6.1)0.41%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)1.1%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (6.5)0.92%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.1)0.53%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)0.97%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)1.1%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
AnalizadaCrítica (9.8)0.97%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.1)0.55%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.1)0.86%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202622/9/2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.9)0.47%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.1)0.69%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (6.5)0.64%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
AnalizadaMedia (6.5)0.84%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition8/9/202629/9/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.