Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

2649 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.9)0.48%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database. This vulnerability is due to certain parameters being concatenated directly into SQL clauses without parameterization. An attacker could exploit…
AnalizadaMedia (4.9)0.46%—Cisco Identity Services Engine16/9/202628/9/2026
A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. This vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity…
AnalizadaMedia (4.9)0.48%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the monitoring database. This vulnerability is due to insufficient validation of specific parameters that are then concatenated into an SQL statement. An attacker could…
AnalizadaAlta (7.6)0.41%—Cisco Identity Services Engine16/9/202628/9/2026
A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query. An attacker could exploit this vulnerability…
AnalizadaAlta (7.2)0.92%—Cisco Identity Services Engine16/9/202628/9/2026
A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path. A successful…
Pendiente de análisisAlta (8.6)0.40%—Cisco Identity Services EngineAI16/9/202618/9/2026
A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by…
Pendiente de análisisMedia (6.1)0.19%—Cisco Identity Services EngineAI16/9/202618/9/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly…
Pendiente de análisisMedia (6.5)0.21%—Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI16/9/202618/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses…
Pendiente de análisisMedia (4.3)0.36%—Cisco Identify Services EngineAI16/9/202618/9/2026
A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker…
Pendiente de análisisMedia (4.3)0.36%—Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI16/9/202618/9/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation…
Pendiente de análisisMedia (4.9)0.29%—Cisco Identity Services EngineAI16/9/202622/9/2026
A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of…
Pendiente de análisisCrítica (9.1)0.33%—Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI16/9/202618/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses…
Pendiente de análisisCrítica (9.1)0.45%—Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI16/9/202618/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses…
AnalizadaCrítica (10)0.46%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses…
AnalizadaCrítica (10)0.40%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses…
AnalizadaCrítica (9.9)0.37%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses…
AplazadaAlta (7.1)0.44%—Reengine RengineAI16/9/202623/9/2026
reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can access files containing third-party API keys for services like SecurityTrails,…
Pendiente de análisisAlta (7.1)0.24%—Oracle Agile Engineering Data ManagementAI15/9/202617/9/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to…
Pendiente de análisisAlta (7.3)0.14%—Oracle Agile Engineering Data ManagementAI15/9/202617/9/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering…
Pendiente de análisisAlta (7.3)0.23%—Oracle Agile Engineering Data ManagementAI15/9/202617/9/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to…
Pendiente de análisisAlta (8.4)0.14%—Oracle Agile Engineering Data ManagementAI15/9/202617/9/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering…
Pendiente de análisisAlta (7.8)0.14%—Oracle Peoplesoft Enterprise FIN Engineering BrazilAI15/9/202617/9/2026
Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Engineering Brazil…
Pendiente de análisisCrítica (9.3)1.1%—Tencent Mass Service EngineAI15/9/202622/9/2026
Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.
Pendiente de análisisAlta (7.7)0.37%—Oracle E-business SuiteAIOracle EngineeringAI15/9/202621/9/2026
Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering. While the vulnerability is…
AplazadaMedia (6.5)0.45%—THE AI EngineAI15/9/202615/9/2026
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with…