Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
22.752 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.44% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (5.4) | 0.23% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.5) | 0.45% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.5) | 0.38% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Alta (8.8) | 0.44% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. | |
| Analizada | Alta (7.2) | 0.46% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (8.8) | 0.44% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. | |
| Analizada | Alta (7.2) | 2.0% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Alta (8.8) | 2.3% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Alta (7.2) | 0.27% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Aplazada | Media (6.5) | 0.30% | — | Taxi Booking ManagerAI | 19/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions. | |
| Aplazada | Alta (8.5) | 0.32% | — | Advancedfilemanager Advanced File ManagerAI | 19/8/2026 | 26/8/2026 | The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Hyperion Financial Management | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.… | |
| Analizada | Media (4.2) | 0.11% | — | Oracle Hyperion Financial Management | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to… | |
| Analizada | Media (5.3) | 0.32% | — | Oracle Hyperion Financial Management | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.… | |
| Analizada | Media (4.2) | 0.22% | — | Oracle Hyperion Financial Management | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.… | |
| Analizada | Baja (1.9) | 0.13% | — | Oracle Hyperion Financial Management | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to… | |
| Analizada | Media (4.4) | 0.17% | — | Oracle Hyperion Financial Management | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.… | |
| Analizada | Baja (3) | 0.13% | — | Oracle Hyperion Financial Management | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Communications Unified Inventory Management | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Third Party). Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0-7.8.0 and 8.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Communications Unified Inventory Management | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component). Supported versions that are affected are 7.5.0-7.5.1, 7.6.0-7.8.0 and 8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Analizada | Media (4.3) | 0.33% | — | Oracle Access Manager | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authorization Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Access Manager.… | |
| Modificada | Media (5.4) | 0.13% | — | Oracle Hyperion Financial Management | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.… | |
| Analizada | Media (6.5) | 0.34% | — | Oracle Hyperion Financial Management | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.… | |
| Analizada | Media (5.3) | 0.29% | — | Oracle Hyperion Financial Management | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.… |