Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
3843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.39% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of… | |
| Analizada | Alta (7.1) | 0.33% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Application Testing Suite executes to compromise Oracle… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks require human… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Applications Platform Engineering | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Applications Platform Engineering product of Oracle E-Business Suite (component: Valid Session). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Applications… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Mobile Application Server | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Applications DBA | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: JRI and other Java utils). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications DBA.… | |
| Analizada | Alta (7.1) | 0.38% | — | Oracle Applications DBA | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Peoplesoft Enterprise CC Common Application Objects | 18/8/2026 | 4/9/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise PeopleSoft… | |
| Analizada | Crítica (9.4) | 0.55% | — | IBM Websphere Application Server | 13/8/2026 | 17/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. | |
| Analizada | Media (5.3) | 0.59% | — | IBM Websphere Application Server | 13/8/2026 | 17/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled. | |
| Analizada | Alta (8.1) | 0.42% | — | IBM Websphere Application Server | 12/8/2026 | 17/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives. | |
| Pendiente de análisis | Media (6.3) | 0.35% | — | SAP Netweaver Application Server AbapAI | 11/8/2026 | 26/8/2026 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed and reflected within the DOM on the client side during… | |
| Pendiente de análisis | Media (5.5) | 0.69% | — | SAP Netweaver Application Server AbapAISAP Abap PlatformAI | 11/8/2026 | 26/8/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or… | |
| Pendiente de análisis | Media (6.3) | 0.29% | — | SAP Netweaver Application Server JavaAIAdobe Document ServiceAI | 11/8/2026 | 26/8/2026 | SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though… | |
| Pendiente de análisis | Crítica (9.8) | 0.64% | — | SAP Netweaver Application Server AbapAI | 11/8/2026 | 26/8/2026 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and… | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | Datadog Android ApplicationAIGoogle Firebase CrashlyticsAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems. | |
| Pendiente de análisis | Media (6.3) | 0.24% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend. This requires a… | |
| Pendiente de análisis | Media (4.6) | 0.24% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recipient, service, tags, and on-call/incident deep links) and SearchRecentDatabase (the user's full in-app search history).… | |
| Pendiente de análisis | Media (6.4) | 0.29% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the activity closes and no in-process session matches that ID, it unconditionally cancels notification ID 9201 (the Bits AI… | |
| Pendiente de análisis | Media (5.5) | 0.16% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, DashboardWidgetActivity) are exported with no permission guard. Each accepts a… | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Application Insights Profiler | 7/8/2026 | 17/8/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. |