Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
4639 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.34% | — | Oracle Field ServiceAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of… | |
| Aplazada | Alta (7.1) | 0.29% | — | Oracle Field ServiceAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks… | |
| Pendiente de análisis | Alta (7.6) | 0.31% | — | Oracle Field ServiceAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle Service Delivery PlatformAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform.… | |
| Pendiente de análisis | Crítica (9.9) | 0.42% | — | Oracle Service Delivery PlatformAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Service Delivery Platform.… | |
| Pendiente de análisis | Crítica (9.9) | 0.42% | — | Oracle Service Delivery PlatformAIOracle Fusion MiddlewareAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery… | |
| Pendiente de análisis | Crítica (9.9) | 0.42% | — | Oracle Service Delivery PlatformAIOracle Fusion MiddlewareAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery… | |
| Pendiente de análisis | Crítica (9.3) | 1.1% | — | Tencent Mass Service EngineAI | 15/9/2026 | 22/9/2026 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root. | |
| Aplazada | Alta (7.4) | 0.36% | — | Oracle WEB Services ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Web Services… | |
| Aplazada | Alta (8.2) | 0.34% | — | Oracle WEB Services ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Agent). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services… | |
| Aplazada | Media (5.4) | 0.21% | — | Oracle Field ServiceAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks… | |
| Aplazada | Crítica (9.1) | 0.47% | — | Oracle Siebel Apps - Financial ServicesAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Financial Services.… | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Atlassian Jira Service Management Data CenterAI | 15/9/2026 | 17/9/2026 | This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. * Jira Service Management Data Center 11.3: Upgrade to a release greater than or equal to 11.3.11 | |
| Pendiente de análisis | Media (5.9) | 0.41% | — | Redhat Service InterconnectAIRedhat Skupper RouterAI | 10/9/2026 | 14/9/2026 | A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing,… | |
| Aplazada | Alta (8.6) | 0.60% | — | Behavioral Technology Group PavlokAIApple Notification Center ServiceAI | 10/9/2026 | 10/9/2026 | A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local… | |
| Pendiente de análisis | Media (6.6) | 0.31% | — | Tanium Data ServiceAI | 9/9/2026 | 9/9/2026 | Tanium addressed a path traversal vulnerability in Tanium Data Service. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Xbox Gaming Services | 8/9/2026 | 14/9/2026 | Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Alta (8.8) | 0.24% | — | TAC Information Services Internal AND External Trade INC Goldenhorn OneitAI | 4/9/2026 | 8/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN ONEIT: before Göbeklitepe. | |
| Aplazada | Alta (7) | 0.34% | — | BR Industrial Automation Gmbh Mapp AuditAIBR Industrial Automation Gmbh Mapp ServicesAI | 3/9/2026 | 3/9/2026 | Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0. | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Fast-note-sync-serviceAI | 1/9/2026 | 8/9/2026 | An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey | |
| Aplazada | Media (5.9) | 1.1% | — | Sage Employee Self ServiceAI | 1/9/2026 | 9/9/2026 | A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants, an attacker may bypass directory restrictions and access files outside the application's intended… | |
| Pendiente de análisis | Crítica (10) | 0.42% | — | Servicenow AI PlatformAI | 27/8/2026 | 1/9/2026 | ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data… | |
| Pendiente de análisis | Crítica (10) | 0.62% | — | Servicenow AI PlatformAI | 27/8/2026 | 1/9/2026 | ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended. ServiceNow… | |
| Pendiente de análisis | Crítica (10) | 5.0% | — | Servicenow AI PlatformAI | 27/8/2026 | 3/9/2026 | ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a… |