Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

5399 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.61%—Velocloud EdgeAI16/9/202617/9/2026
Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the…
AplazadaAlta (8.2)0.28%—Oracle Siebel CRM Cloud ApplicationsAI15/9/202617/9/2026
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the…
AplazadaAlta (8.8)0.42%—Oracle Siebel CRM Cloud ApplicationsAI15/9/202617/9/2026
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful…
AplazadaAlta (7.9)0.16%—Oracle Siebel CRM Cloud ApplicationsAI15/9/202617/9/2026
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to…
Pendiente de análisisMedia (5.4)0.25%—Oracle Communications Cloud Native Core Security Edge Protection ProxyAI15/9/202622/9/2026
Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
Pendiente de análisisAlta (8.2)0.28%—Oracle Communications Cloud Native Core Security Edge Protection ProxyAI15/9/202618/9/2026
Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…
Pendiente de análisisAlta (7.1)0.25%—Oracle Communications Cloud Native Core Security Edge Protection ProxyAI15/9/202622/9/2026
Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication…
Pendiente de análisisMedia (6.5)0.22%—IBM Cloud PAK FOR Business AutomationAI15/9/202616/9/2026
IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive…
Pendiente de análisisAlta (8.8)0.75%—OpencostAIGoogle Cloud PlatformAI15/9/202630/9/2026
OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and submit an arbitrary key form value that is written to the GCP service-account…
AnalizadaMedia (5.4)0.20%—IBM Cloud PAK FOR Business Automation15/9/202623/9/2026
IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
AnalizadaMedia (5.4)0.17%—IBM Cloud PAK FOR Business Automation15/9/202623/9/2026
IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaMedia (5.4)0.17%—IBM Cloud PAK FOR Business Automation15/9/202623/9/2026
IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AplazadaAlta (7.1)0.31%—Jhb.software Payload Cloudinary PluginAIPayload CMSAI15/9/202630/9/2026
Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payload-cloudinary-plugin deployments with clientUploads enabled expose POST /api/cloudinary-generate-signature, whose handler in cloudinary/src/getGenerateSignature.ts passes attacker-controlled…
AplazadaCrítica (9.3)0.64%—Yonyou U8 CloudAI15/9/202624/9/2026
Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction method, which…
Pendiente de análisisAlta (7.7)0.52%—Google Cloud Gemini Enterprise Agent Platform SDK FOR PythonAI15/9/202621/9/2026
Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.
AplazadaAlta (8.7)0.50%—Tangyh Lamp-cloudAI15/9/202622/9/2026
lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getProperties to retrieve sensitive information including JVM classpath, filesystem paths,…
AplazadaCrítica (9.3)0.88%—Pig4cloud PIGAI15/9/202624/9/2026
pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the…
Pendiente de análisisMedia (6.5)0.22%—IBM Cloud PAK FOR Business AutomationAI14/9/202616/9/2026
IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.
Pendiente de análisisMedia (5.4)0.18%—IBM Cloud PAK FOR Business AutomationAI14/9/202616/9/2026
IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.
Pendiente de análisisAlta (8.2)0.21%—IBM Cloud PAK FOR Data SystemAI14/9/202616/9/2026
IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.
AnalizadaAlta (8.8)0.42%—IBM Datastage ON Cloud PAK FOR Data14/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.
AnalizadaAlta (8.8)0.91%—IBM Datastage ON Cloud PAK FOR Data14/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.
AnalizadaMedia (6.5)0.34%—IBM Datastage ON Cloud PAK FOR Data14/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
AnalizadaAlta (8.8)0.54%—IBM Datastage ON Cloud PAK FOR Data14/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.
AnalizadaAlta (8.8)0.43%—IBM Datastage ON Cloud PAK FOR Data14/9/20266/10/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.