Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1832 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.85% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | |
| Analizada | Alta (8.8) | 0.43% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality,… | |
| Analizada | Alta (8.6) | 0.37% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and… | |
| Analizada | Alta (8.8) | 0.36% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation of user supplied input. | |
| Analizada | Alta (8.8) | 0.63% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system. | |
| Analizada | Crítica (9.8) | 0.56% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the… | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (8.2) | 0.28% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (7.1) | 0.25% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication… | |
| Pendiente de análisis | Media (5.9) | 0.10% | — | Paloaltonetworks GlobalprotectAI | 10/9/2026 | 11/9/2026 | Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. This… | |
| Aplazada | Alta (7.2) | 0.47% | — | Cleantalk Spam Protection Honeypot Anti SpamAI | 5/9/2026 | 8/9/2026 | The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including, 6.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| En análisis | Media (6.5) | 0.41% | — | Dell Powerprotect Data ManagerAI | 3/9/2026 | 5/9/2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass. | |
| En análisis | Media (4.1) | 0.36% | — | Dell Powerprotect Data ManagerAI | 3/9/2026 | 3/9/2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure. | |
| En análisis | Alta (7.8) | 0.20% | — | Dell Powerprotect Data ManagerAI | 3/9/2026 | 4/9/2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure. | |
| En análisis | Media (6.8) | 0.38% | — | Dell Powerprotect Data ManagerAI | 3/9/2026 | 4/9/2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of phishing attacks. | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Aplazada | Media (5.3) | 0.21% | — | WP Edit Password ProtectedAI | 2/9/2026 | 3/9/2026 | The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API. | |
| Analizada | Baja (3.7) | 0.32% | — | Captcha Protected Page Project Captcha Protected Page | 2/9/2026 | 9/9/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2. | |
| Analizada | Alta (7.8) | 0.17% | — | Dell Powerprotect Cyber Recovery | 26/8/2026 | 1/9/2026 | Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection. | |
| Analizada | Alta (8.8) | 0.46% | — | Dell Powerprotect Cyber Recovery | 26/8/2026 | 1/9/2026 | Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (7.5) | 0.22% | — | Dell Powerprotect ONE | 26/8/2026 | 28/8/2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | |
| Analizada | Media (6.5) | 0.31% | — | Dell Powerprotect ONE | 26/8/2026 | 28/8/2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering. | |
| Analizada | Alta (8.8) | 2.0% | — | Dell Powerprotect ONE | 26/8/2026 | 28/8/2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Alta (7.5) | 0.48% | — | Dell Powerprotect ONE | 26/8/2026 | 28/8/2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. | |
| Analizada | Alta (8.8) | 1.7% | — | Dell Powerprotect ONE | 26/8/2026 | 28/8/2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |