Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
5399 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.61% | — | Velocloud EdgeAI | 16/9/2026 | 17/9/2026 | Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the… | |
| Aplazada | Alta (8.2) | 0.28% | — | Oracle Siebel CRM Cloud ApplicationsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Siebel CRM Cloud ApplicationsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful… | |
| Aplazada | Alta (7.9) | 0.16% | — | Oracle Siebel CRM Cloud ApplicationsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to… | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (8.2) | 0.28% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (7.1) | 0.25% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication… | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Cloud PAK FOR Business AutomationAI | 15/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive… | |
| Pendiente de análisis | Alta (8.8) | 0.75% | — | OpencostAIGoogle Cloud PlatformAI | 15/9/2026 | 30/9/2026 | OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and submit an arbitrary key form value that is written to the GCP service-account… | |
| Analizada | Media (5.4) | 0.20% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Alta (7.1) | 0.31% | — | Jhb.software Payload Cloudinary PluginAIPayload CMSAI | 15/9/2026 | 30/9/2026 | Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payload-cloudinary-plugin deployments with clientUploads enabled expose POST /api/cloudinary-generate-signature, whose handler in cloudinary/src/getGenerateSignature.ts passes attacker-controlled… | |
| Aplazada | Crítica (9.3) | 0.64% | — | Yonyou U8 CloudAI | 15/9/2026 | 24/9/2026 | Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction method, which… | |
| Pendiente de análisis | Alta (7.7) | 0.52% | — | Google Cloud Gemini Enterprise Agent Platform SDK FOR PythonAI | 15/9/2026 | 21/9/2026 | Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft. | |
| Aplazada | Alta (8.7) | 0.50% | — | Tangyh Lamp-cloudAI | 15/9/2026 | 22/9/2026 | lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getProperties to retrieve sensitive information including JVM classpath, filesystem paths,… | |
| Aplazada | Crítica (9.3) | 0.88% | — | Pig4cloud PIGAI | 15/9/2026 | 24/9/2026 | pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the… | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Cloud PAK FOR Business AutomationAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Cloud PAK FOR Business AutomationAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers. | |
| Pendiente de análisis | Alta (8.2) | 0.21% | — | IBM Cloud PAK FOR Data SystemAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols. | |
| Analizada | Alta (8.8) | 0.42% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property. | |
| Analizada | Alta (8.8) | 0.91% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection. | |
| Analizada | Media (6.5) | 0.34% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | |
| Analizada | Alta (8.8) | 0.54% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine. | |
| Analizada | Alta (8.8) | 0.43% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths. |