Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.48% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/9/2026 | 28/9/2026 | A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database. This vulnerability is due to certain parameters being concatenated directly into SQL clauses without parameterization. An attacker could exploit… | |
| Analizada | Media (4.9) | 0.46% | — | Cisco Identity Services Engine | 16/9/2026 | 28/9/2026 | A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. This vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity… | |
| Analizada | Media (4.9) | 0.48% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/9/2026 | 28/9/2026 | A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the monitoring database. This vulnerability is due to insufficient validation of specific parameters that are then concatenated into an SQL statement. An attacker could… | |
| Analizada | Alta (7.6) | 0.41% | — | Cisco Identity Services Engine | 16/9/2026 | 28/9/2026 | A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query. An attacker could exploit this vulnerability… | |
| Analizada | Alta (7.2) | 0.92% | — | Cisco Identity Services Engine | 16/9/2026 | 28/9/2026 | A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path. A successful… | |
| Pendiente de análisis | Alta (8.6) | 0.40% | — | Cisco Identity Services EngineAI | 16/9/2026 | 18/9/2026 | A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by… | |
| Pendiente de análisis | Media (6.1) | 0.19% | — | Cisco Identity Services EngineAI | 16/9/2026 | 18/9/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly… | |
| Pendiente de análisis | Media (6.5) | 0.21% | — | Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Pendiente de análisis | Media (4.3) | 0.36% | — | Cisco Identify Services EngineAI | 16/9/2026 | 18/9/2026 | A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker… | |
| Pendiente de análisis | Media (4.3) | 0.36% | — | Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI | 16/9/2026 | 18/9/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation… | |
| Pendiente de análisis | Media (4.9) | 0.29% | — | Cisco Identity Services EngineAI | 16/9/2026 | 22/9/2026 | A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of… | |
| Pendiente de análisis | Crítica (9.1) | 0.33% | — | Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Pendiente de análisis | Crítica (9.1) | 0.45% | — | Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Analizada | Crítica (10) | 0.46% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/9/2026 | 28/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Analizada | Crítica (10) | 0.40% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/9/2026 | 28/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Analizada | Crítica (9.9) | 0.37% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/9/2026 | 28/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Aplazada | Alta (7.1) | 0.44% | — | Reengine RengineAI | 16/9/2026 | 23/9/2026 | reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can access files containing third-party API keys for services like SecurityTrails,… | |
| Pendiente de análisis | Alta (7.1) | 0.24% | — | Oracle Agile Engineering Data ManagementAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to… | |
| Pendiente de análisis | Alta (7.3) | 0.14% | — | Oracle Agile Engineering Data ManagementAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering… | |
| Pendiente de análisis | Alta (7.3) | 0.23% | — | Oracle Agile Engineering Data ManagementAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to… | |
| Pendiente de análisis | Alta (8.4) | 0.14% | — | Oracle Agile Engineering Data ManagementAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | Oracle Peoplesoft Enterprise FIN Engineering BrazilAI | 15/9/2026 | 17/9/2026 | Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Engineering Brazil… | |
| Pendiente de análisis | Crítica (9.3) | 1.1% | — | Tencent Mass Service EngineAI | 15/9/2026 | 22/9/2026 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root. | |
| Pendiente de análisis | Alta (7.7) | 0.37% | — | Oracle E-business SuiteAIOracle EngineeringAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering. While the vulnerability is… | |
| Aplazada | Media (6.5) | 0.45% | — | THE AI EngineAI | 15/9/2026 | 15/9/2026 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… |