Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2771▲ 6 respecto a la semana anterior
Críticas / altas1285▼ 246 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
–

14.294 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)78%⚠ Explotación activa💥 ExploitCheckpoint Multi-domain Security ManagementCheckpoint Quantum Security Management22/7/202610/8/2026
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security…
AplazadaAlta (8.8)0.14%—Servereye ClientAIServereye SensorhubAIServereye ClientagentcontainerserviceAI22/7/202622/7/2026
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory…
AplazadaMedia (6.4)0.42%—Brainstormforce Ultimate Addons FOR ElementorAI22/7/202622/7/2026
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AnalizadaAlta (7.5)0.28%—Oracle Complex Maintenance Repair AND Overhaul21/7/202619/8/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex…
AnalizadaAlta (7.2)0.49%—Oracle Advanced Supply Chain Planning21/7/202617/8/2026
Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Supply Chain Planning.…
AnalizadaMedia (5.4)0.23%—Oracle Complex Maintenance Repair AND Overhaul21/7/20263/8/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Common Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex…
AnalizadaMedia (6.8)0.29%—Oracle Peoplesoft Enterprise CS Financial AID21/7/20265/8/2026
Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Financial Aid.…
AnalizadaMedia (6.1)0.15%—Oracle Peoplesoft Enterprise CS Financial AID21/7/20265/8/2026
Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Institutional Methodology Need Analysis). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise…
AnalizadaMedia (5.5)0.17%—Oracle Peoplesoft Enterprise CS Financial AID21/7/20265/8/2026
Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: FM Need Analysis Calculator). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise CS Financial…
AplazadaCrítica (9.1)0.86%—Ammos Instrument Toolkit Binary Stream CaptureAINasa AIT CoreAI21/7/202623/7/2026
The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing for instrument and CubeSat Missions. In…
AnalizadaCrítica (9.8)0.51%—Oracle Retail Integration BUS21/7/202631/7/2026
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful…
AnalizadaCrítica (9.8)0.51%—Oracle Retail Integration BUS21/7/202631/7/2026
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful…
AnalizadaAlta (7.4)0.34%—Oracle Retail Eftlink21/7/20267/8/2026
Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported versions that are affected are 21.0.0-25.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Retail EFTLink. Successful attacks of…
AnalizadaMedia (4.3)0.27%—Oracle Retail Xstore Point OF Service21/7/20267/8/2026
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of…
AnalizadaBaja (3.3)0.14%—Oracle Retail Xstore Point OF Service21/7/20267/8/2026
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service…
AplazadaAlta (7.5)0.51%—AiflowyAI21/7/202622/7/2026
SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPageData method in the DatacenterQuery.java file
AplazadaMedia (6.1)0.30%—AiflowyAI21/7/202622/7/2026
Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the UploadController.java file
AplazadaAlta (7.5)0.52%—AiflowyAI21/7/202622/7/2026
An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.
AplazadaCrítica (9.8)0.73%—Bytebot-aiAI21/7/202622/7/2026
An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`.
AplazadaAlta (8.1)0.72%—Dayuanjiang Next-ai-draw-ioAI21/7/202622/7/2026
Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter
AplazadaAlta (7.8)0.63%—Dayuanjiang Next-ai-draw-ioAI21/7/202622/7/2026
Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server
AplazadaAlta (7.5)0.51%—Dayuanjiang Next-ai-draw-ioAI21/7/202622/7/2026
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component
AplazadaCrítica (9.8)0.62%—Dayuanjiang Next-ai-draw-ioAI21/7/202622/7/2026
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value
AplazadaMedia (6.9)0.33%—TaigaAI21/7/202630/9/2026
Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project by supplying a project ID to the filters_data API endpoints on UserStory, Task, Issue, and Epic viewsets. Attackers can send…
AplazadaAlta (8.3)0.39%—Praisonai PlatformAI21/7/202622/7/2026
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/agents/{agent_id}`) gate access on `require_workspace_member(workspace_id)` only, then…