Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2286 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.35% | — | Oracle E-business SuiteAIOracle CRM Technical FoundationAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Application Framework). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical… | |
| Aplazada | Alta (7.1) | 0.36% | — | Oracle ONE TO ONE FulfillmentAIOracle E Business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful… | |
| Aplazada | Alta (8.5) | 0.29% | — | Oracle Sales OnlineAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: OSO Other). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online. While the vulnerability is in… | |
| Aplazada | Alta (7.1) | 0.28% | — | Oracle One-to-one FulfillmentAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. While the… | |
| Aplazada | Alta (7.5) | 0.42% | — | Oracle Application Object LibraryAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful… | |
| Aplazada | Alta (8.1) | 0.35% | — | Oracle Project IntelligenceAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.… | |
| Aplazada | Alta (7.6) | 0.15% | — | Oracle Sales OnlineAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online. Successful attacks… | |
| Aplazada | Alta (7.7) | 0.37% | — | Oracle Order ManagementAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the… | |
| Aplazada | Alta (7.5) | 0.39% | — | Oracle Applications ManagerAIOracle E-business SuiteAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.… | |
| Aplazada | Alta (7.1) | 0.29% | — | Oracle E-business SuiteAIOracle QualityAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this… | |
| Pendiente de análisis | Alta (7.1) | 0.36% | — | IBM Business Automation WorkflowAI | 15/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource. | |
| Pendiente de análisis | Media (5.4) | 0.17% | — | IBM Business Automation WorkflowAI | 15/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Cloud PAK FOR Business AutomationAI | 15/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive… | |
| Analizada | Media (5.4) | 0.20% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Cloud PAK FOR Business AutomationAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Cloud PAK FOR Business AutomationAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers. | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | IBM Business Automation WorkflowAI | 14/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Pendiente de análisis | Alta (7.1) | 0.28% | — | IBM Business Automation WorkflowAI | 14/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default. | |
| Analizada | Alta (8.3) | 0.32% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. |