Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 5.5% | 💥 Exploit | Ruby-vips Image ProcessingAIImagemagick Mini MagickAIRubyonrails Active StorageAI | 30/1/2026 | 15/7/2026 | # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command… | |
| Analizada | Crítica (9.8) | 0.48% | — | Oracle Agile Product Lifecycle Management FOR Process | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product… | |
| Analizada | Media (6.8) | 0.33% | — | Oracle Agile Product Lifecycle Management FOR Process | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile… | |
| Analizada | Crítica (9.3) | 0.26% | — | Aveva Process Optimization | 16/1/2026 | 17/6/2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server. | |
| Analizada | Alta (8.5) | 0.22% | — | Aveva Process Optimization | 16/1/2026 | 17/6/2026 | The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements. | |
| Analizada | Alta (7.6) | 0.17% | — | Aveva Process Optimization | 16/1/2026 | 17/6/2026 | The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-middle or passive inspection scenarios. | |
| Analizada | Alta (8.6) | 0.19% | — | Aveva Process Optimization | 16/1/2026 | 17/6/2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files. | |
| Analizada | Crítica (9.3) | 0.29% | — | Aveva Process Optimization | 16/1/2026 | 17/6/2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS system, potentially resulting in complete compromise of the model application server. | |
| Analizada | Crítica (9.3) | 0.33% | — | Aveva Process Optimization | 16/1/2026 | 17/6/2026 | The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server. | |
| Analizada | Crítica (10) | 1.5% | — | Aveva Process Optimization | 16/1/2026 | 17/6/2026 | The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” service, potentially resulting in complete compromise of the model application server. | |
| Modificada | Crítica (9.6) | 1.3% | 💥 PoC | Redhat Build OF Apache CamelRedhat Data GridRedhat FuseRedhat Jboss Enterprise Application Platform+4 | 7/1/2026 | 6/10/2026 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling… | |
| Aplazada | Alta (8.7) | 0.24% | — | 3DS Delmia Service Process EngineerAI | 24/11/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Aplazada | Media (5.4) | 0.11% | — | Intel Processor Identification UtilityAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Media (5.4) | 0.11% | — | Intel Processor Identification UtilityAI | 11/11/2025 | 17/6/2026 | Incorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable local code execution. This result may… | |
| Aplazada | Alta (8.5) | 0.24% | — | Intel Processor Identification UtilityAI | 11/11/2025 | 17/6/2026 | Use of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This… | |
| Aplazada | Alta (7.5) | 0.43% | — | Processby Lazy Load OptimizerAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Processby Lazy Load Optimizer lazy-load-optimizer allows PHP Local File Inclusion.This issue affects Lazy Load Optimizer: from n/a through <= 1.4.7. | |
| Aplazada | Alta (7.5) | 0.43% | — | Processby Responsive SidebarAIPHPAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Processby Responsive Sidebar responsive-sidebar allows PHP Local File Inclusion.This issue affects Responsive Sidebar: from n/a through <= 1.2.2. | |
| Analizada | Media (6.1) | 0.20% | — | IBM Business Automation WorkflowIBM Process Federation Server | 6/11/2025 | 17/6/2026 | IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an… | |
| Analizada | Media (6.5) | 0.43% | — | Processwire | 21/10/2025 | 17/6/2026 | ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service. | |
| Modificada | Media (5.5) | 0.42% | — | Fabian Student Transcript Processing System | 8/10/2025 | 17/6/2026 | A weakness has been identified in itsourcecode Student Transcript Processing System 1.0. Affected is an unknown function of the file /login.php. Executing a manipulation of the argument uname can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Oracle Concurrent Processing | 5/10/2025 | 4/8/2026 | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing.… | |
| Analizada | Crítica (9.8) | 0.40% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+223 | 24/9/2025 | 17/6/2026 | Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+223 | 24/9/2025 | 25/9/2026 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Sm8750 FirmwareQualcomm Sm8750p FirmwareQualcomm Sm8850 FirmwareQualcomm Sm8850p Firmware+169 | 24/9/2025 | 25/9/2026 | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. | |
| Modificada | Alta (7.5) | 2.3% | 💥 PoC | Redhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+4 | 2/9/2025 | 6/10/2026 | A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol… |