Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
5082 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 2.7% | — | Sangfor Operation AND Maintenance Security Management SystemAI | 3/8/2026 | 12/8/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack… | |
| Pendiente de análisis | Crítica (9.3) | 0.89% | 💥 PoC | Checkpoint Security Management ServerAICheckpoint Multi Domain Security Management ServerAI | 3/8/2026 | 5/8/2026 | An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could… | |
| Pendiente de análisis | Alta (8.5) | 0.19% | — | Redhat Advanced Cluster Security FOR KubernetesAI | 31/7/2026 | 3/8/2026 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the… | |
| Pendiente de análisis | Alta (7.8) | 0.20% | — | Gdata Total SecurityAI | 29/7/2026 | 30/7/2026 | G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Pendiente de análisis | Crítica (9.2) | 0.50% | — | Synopsys Coverity ConnectAIVmware Spring SecurityAI | 29/7/2026 | 30/7/2026 | A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data… | |
| Aplazada | Media (5.2) | 0.24% | — | Tridium Niagara FrameworkAITridium Niagara Enterprise SecurityAI | 23/7/2026 | 23/7/2026 | Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before… | |
| Aplazada | Alta (7.5) | 0.53% | — | Security Ninja PremiumAI | 23/7/2026 | 23/7/2026 | The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor… | |
| Analizada | Alta (8.8) | 0.47% | — | Oracle Platform Security FOR Java | 22/7/2026 | 24/7/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Platform Security FOR Java | 22/7/2026 | 24/7/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.8) | 0.47% | — | Oracle Platform Security FOR Java | 22/7/2026 | 24/7/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.8) | 0.47% | — | Oracle Platform Security FOR Java | 22/7/2026 | 24/7/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (9.8) | 0.55% | — | Oracle Platform Security FOR Java | 22/7/2026 | 24/7/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8) | 0.27% | — | Oracle Platform Security FOR Java | 22/7/2026 | 24/7/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Platform Security FOR Java | 22/7/2026 | 24/7/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (9.9) | 0.47% | — | Oracle Platform Security FOR Java | 22/7/2026 | 24/7/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.8) | 0.55% | — | Oracle Platform Security FOR Java | 22/7/2026 | 24/7/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle… | |
| Analizada | Crítica (9.8) | 0.55% | — | Oracle Platform Security FOR Java | 22/7/2026 | 24/7/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (10) | 0.55% | — | Oracle Platform Security FOR Java | 22/7/2026 | 23/7/2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Pendiente de análisis | Crítica (9.1) | 1.0% | — | Checkpoint Security ManagementAICheckpoint Multi-domain Security ManagementAI | 22/7/2026 | 24/7/2026 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation… | |
| Analizada | Crítica (9.3) | 78% | ⚠ Explotación activa💥 Exploit | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/7/2026 | 10/8/2026 | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security… | |
| Analizada | Media (6.4) | 0.14% | — | Oracle Security Service | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Security Service. Successful attacks… | |
| Analizada | Alta (8.7) | 2.2% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability. | |
| Analizada | Alta (7.1) | 0.32% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access. | |
| Analizada | Crítica (9.4) | 2.3% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality. | |
| Analizada | Crítica (9.4) | 0.80% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint. |