Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
8446 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.26% | — | GimpRedhat Enterprise Linux | 24/8/2026 | 1/9/2026 | A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service… | |
| Aplazada | Alta (8.3) | 0.22% | — | ARC EnterpriseAI | 21/8/2026 | 9/9/2026 | Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/cluster/replication/receiver.go` validates only the wire-format envelope (length, opcode) of inbound messages. The `MsgReplicateSync` payload itself is accepted without… | |
| Analizada | Media (6.5) | 0.43% | — | Redhat Enterprise LinuxFreeipa | 20/8/2026 | 24/8/2026 | A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service,… | |
| Modificada | Alta (7.5) | 0.43% | — | Redhat Enterprise LinuxFreeipa | 20/8/2026 | 28/9/2026 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS)… | |
| Modificada | Alta (7.5) | 0.43% | — | Redhat Enterprise LinuxFreeipa | 20/8/2026 | 28/9/2026 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage,… | |
| Modificada | Alta (8.7) | 0.43% | — | Redhat Enterprise LinuxFreeipa | 20/8/2026 | 28/9/2026 | A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service… | |
| Modificada | Alta (8.1) | 0.22% | — | FreeipaRedhat Enterprise Linux | 20/8/2026 | 28/9/2026 | A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS)… | |
| Analizada | Media (5.3) | 0.39% | — | Cisco Talos Intelligence FOR Enterprise Security Cloud | 19/8/2026 | 21/8/2026 | In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and… | |
| Analizada | Alta (8.8) | 0.42% | — | Cisco Talos Intelligence FOR Enterprise Security Cloud | 19/8/2026 | 21/8/2026 | In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the instance to make an outbound request to… | |
| Analizada | Alta (8.1) | 0.35% | — | Splunk Enterprise Security | 19/8/2026 | 25/8/2026 | In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) search macros that scheduled searches run with administrator permissions, allowing for access to all relevant data and system integrity through… | |
| Analizada | Alta (8.1) | 0.40% | — | Splunk Enterprise Security | 19/8/2026 | 25/8/2026 | In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for access to all relevant data and system integrity available to the… | |
| Pendiente de análisis | Media (5) | 0.44% | — | Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI | 19/8/2026 | 20/8/2026 | A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. | |
| Analizada | Alta (8.8) | 0.44% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (5.4) | 0.23% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.5) | 0.45% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.5) | 0.38% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Alta (8.8) | 0.44% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. | |
| Analizada | Alta (7.2) | 0.46% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (8.8) | 0.44% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. | |
| Analizada | Alta (7.2) | 2.0% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Alta (8.8) | 2.3% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Alta (7.2) | 0.27% | — | Dell Openmanage Enterprise | 19/8/2026 | 21/8/2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 18/8/2026 | 4/9/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Financial Services Enterprise Case Management | 18/8/2026 | 11/9/2026 | Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.2 and 8.1.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Media (5.3) | 0.28% | — | Oracle Java SEAIOracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAI | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise… |