Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
2145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.40% | — | Oracle XML GatewayAIOracle E-business SuiteAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this… | |
| Aplazada | Alta (7.1) | 0.40% | — | Oracle XML GatewayAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this… | |
| Aplazada | Alta (7.1) | 0.40% | — | Oracle XML GatewayAIOracle E-business SuiteAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this… | |
| Aplazada | Alta (8.7) | 0.22% | — | DockerAIDocker MCP GatewayAI | 15/9/2026 | 30/9/2026 | MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server structure for direct docker:// references and catalog snapshot imports in… | |
| Pendiente de análisis | Alta (7.5) | 0.40% | — | IBM Sterling File GatewayAI | 14/9/2026 | 16/9/2026 | IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control. | |
| Pendiente de análisis | Media (5.4) | 0.30% | — | IBM Sterling B2B IntegratorAIIBM Sterling File GatewayAI | 14/9/2026 | 16/9/2026 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 Standard Edition could allow a remote authenticated attacker to bypass security restrictions due to improper authentication. | |
| Pendiente de análisis | Media (6.5) | 0.71% | — | Envoy GatewayAIEnvoy ProxyAI | 14/9/2026 | 30/9/2026 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a nil authorization value when a namespace-scoped tenant creates a SecurityPolicy… | |
| Pendiente de análisis | Media (6.4) | 0.41% | — | Envoyproxy Envoy GatewayAI | 14/9/2026 | 25/9/2026 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resource in another namespace without a matching Gateway API ReferenceGrant in the… | |
| Pendiente de análisis | Media (6.5) | 0.71% | — | Envoyproxy Envoy GatewayAI | 14/9/2026 | 30/9/2026 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without limiting decompressed output when a tenant-controlled… | |
| Pendiente de análisis | Media (5.3) | 0.47% | — | Envoy GatewayAI | 14/9/2026 | 25/9/2026 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map without synchronization while HTTPServer.Get writes the same map during… | |
| Pendiente de análisis | Alta (7.4) | 0.35% | — | Envoy GatewayAI | 14/9/2026 | 30/9/2026 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deploy.type=GatewayNamespace, installs a JWT StreamInterceptor but no UnaryInterceptor,… | |
| Pendiente de análisis | Crítica (9.1) | 0.43% | — | Envoyproxy Envoy GatewayAIEnvoyproxy Envoy ProxyAI | 14/9/2026 | 30/9/2026 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redundant separators before is_critical_path evaluates Lua submitted through… | |
| Pendiente de análisis | Media (6.5) | 0.71% | — | Envoyproxy Envoy GatewayAIEnvoyproxy Envoy ProxyAI | 14/9/2026 | 30/9/2026 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary… | |
| Pendiente de análisis | Crítica (9.8) | 0.53% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Alta (7.5) | 0.47% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 16/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Crítica (9.8) | 0.53% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Crítica (9.8) | 0.62% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Crítica (9.8) | 0.40% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Aplazada | Media (5.3) | 0.45% | — | Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI | 14/9/2026 | 16/9/2026 | An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication. | |
| Aplazada | Alta (8.7) | 1.9% | — | Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI | 14/9/2026 | 16/9/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (5.1) | 0.26% | — | Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Crítica (10) | 0.50% | 💥 PoC | Cryptopayment GatewayAI | 13/9/2026 | 14/9/2026 | The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored… | |
| Aplazada | Media (5.9) | 0.16% | — | Payment Gateway PaypayAI | 11/9/2026 | 11/9/2026 | The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as paid, or to cancel or fail them. | |
| Aplazada | Media (6.5) | 0.33% | — | Robokassa Payment Gateway FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. | |
| Analizada | Media (5.5) | 1.8% | — | Dell Secure Connect Gateway | 9/9/2026 | 9/9/2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability,… |