Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2780▲ 24 respecto a la semana anterior
Críticas / altas1288▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
25.937 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 1.5% | ⚠ Explotación activa | Trueconf Server | 19/8/2026 | 21/8/2026 | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function. | |
| Pendiente de análisis | Media (6.8) | 0.15% | — | RenovateAIMend Renovate-ceAIRenovate-ee-serverAIRenovate-ee-workerAI | 19/8/2026 | 8/10/2026 | Renovate versions from 42.68.1 before 42.96.3 and from 43.0.0 before 43.4.4, including the renovate/renovate Docker images, and Mend Renovate CE/EE images (renovate-ce, renovate-ee-server, renovate-ee-worker) from 13.3.0 before 13.6.0, fail to restrict environment variables to an allowlist when spawning child… | |
| Pendiente de análisis | Crítica (9.3) | 0.51% | — | Atlassian Confluence Data CenterAIAtlassian Confluence ServerAI | 18/8/2026 | 26/8/2026 | This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS,… | |
| Analizada | Crítica (9.1) | 0.45% | — | Oracle Database Server | 18/8/2026 | 20/8/2026 | Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Portable Clusterware. Successful attacks of this… | |
| Analizada | Media (5.3) | 0.32% | — | Oracle Database Server | 18/8/2026 | 20/8/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can… | |
| Modificada | Crítica (9.6) | 0.40% | — | Oracle Database Server | 18/8/2026 | 22/8/2026 | Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Crítica (9.6) | 0.40% | — | Oracle Database Server | 18/8/2026 | 20/8/2026 | Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Alta (8.5) | 0.33% | — | Oracle Database Server | 18/8/2026 | 20/8/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS,… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Mobile Application Server | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application… | |
| Modificada | Crítica (9.8) | 0.51% | — | Oracle Weblogic Server | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebLogic… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Weblogic Server | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Weblogic Server | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Weblogic Server | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Weblogic Server | 18/8/2026 | 21/8/2026 | Vulnerabilidad en el producto Oracle WebLogic Server de Oracle Fusion Middleware (componente: Core). Las versiones compatibles afectadas son 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 y 15.1.1.0.0. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso a la red a través de T3, IIOP… | |
| Analizada | Alta (8.1) | 0.38% | — | Oracle Weblogic Server | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Weblogic Server | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Weblogic Server | 18/8/2026 | 21/8/2026 | Vulnerabilidad en el producto Oracle WebLogic Server de Oracle Fusion Middleware (componente: Core). Las versiones compatibles afectadas son 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 y 15.1.1.0.0. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso a la red a través de T3, IIOP… | |
| Analizada | Alta (8.1) | 0.42% | — | Oracle Weblogic Server | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle… | |
| Analizada | Media (5.5) | 0.18% | 💥 PoC | Nvidia Triton Inference Server | 18/8/2026 | 1/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution. | |
| Analizada | Alta (7.5) | 0.67% | — | Nvidia Triton Inference Server | 18/8/2026 | 1/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service. | |
| Analizada | Alta (7.5) | 0.67% | — | Nvidia Triton Inference Server | 18/8/2026 | 1/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service. | |
| Analizada | Crítica (9.8) | 0.73% | 💥 PoC | Nvidia Triton Inference Server | 18/8/2026 | 2/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service. | |
| Analizada | Crítica (9.1) | 0.74% | — | Nvidia Triton Inference Server | 18/8/2026 | 2/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure. | |
| Aplazada | Alta (8.1) | 0.49% | — | Apify MCP ServerAI | 18/8/2026 | 18/9/2026 | The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the trusted Actor standby URL with the attacker-controlled webServerMcpPath from an Actor… | |
| Aplazada | Media (4) | 0.18% | — | Adaguc ServerAI | 18/8/2026 | 18/9/2026 | Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards. Versions prior to 7.2.2 crash with a memory-safety fault when it parses a GeoJSON document whose geometry contains a malformed… |