Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
2493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.23% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.6) | 1.1% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.1) | 0.36% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.4) | 0.21% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Media (5.4) | 0.21% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 0.61% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (5.3) | 0.57% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.8) | 0.23% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | |
| Analizada | Alta (8.8) | 1.1% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | |
| Analizada | Media (6.2) | 0.40% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | |
| Analizada | Alta (7.1) | 0.36% | — | Microsoft Edge | 4/8/2026 | 17/9/2026 | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.4) | 0.92% | — | Microsoft Edge Chromium | 4/8/2026 | 7/8/2026 | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.4) | 0.41% | — | Microsoft Edge | 28/7/2026 | 5/8/2026 | Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Alta (7.4) | 0.92% | — | Microsoft Edge Chromium | 26/7/2026 | 3/8/2026 | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.4) | 0.43% | — | Microsoft Edge Chromium | 26/7/2026 | 3/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.4) | 0.21% | — | Microsoft Edge Chromium | 26/7/2026 | 3/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Knowledge Management | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful… | |
| Analizada | Media (5.9) | 0.27% | — | Oracle Peoplesoft Enterprise FIN General Ledger Argentina | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN General Ledger Argentina product of Oracle PeopleSoft (component: General Ledger). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN General… | |
| Analizada | Media (6.1) | 0.13% | — | Oracle Knowledge Management | 21/7/2026 | 10/8/2026 | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks… | |
| Analizada | Alta (7) | 0.27% | — | Oracle JD Edwards Enterpriseone General Ledger | 21/7/2026 | 6/8/2026 | Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne General Ledger.… | |
| Analizada | Media (5.4) | 0.39% | — | Microsoft Edge Chromium | 17/7/2026 | 21/7/2026 | Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. | |
| Aplazada | Alta (8.5) | 0.16% | — | Siemens ComosAISiemens Designcenter NXAISiemens Simcenter 3DAISiemens Simcenter FemapAI+6 | 14/7/2026 | 5/10/2026 | A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter… | |
| Aplazada | Media (6.8) | 0.17% | — | HedgedocAI | 13/7/2026 | 14/7/2026 | HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export flow created an OAuth2 state value but only checked that it was present rather than validating it against the value expected for the user's session. Because the state was not properly validated, an… | |
| Aplazada | Alta (8.3) | 0.40% | — | HedgedocAINodeca Js-yamlAI | 13/7/2026 | 14/7/2026 | HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bomb due to unsafe processing of the note frontmatter. HedgeDoc parsed frontmatter with js-yaml.load (js-yaml v3) via @hedgedoc/meta-marked, which resolved YAML anchor… |