Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
3709 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.25% | — | Oracle Webcenter Portal | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Portal | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via RMI to compromise Oracle WebCenter Portal. Successful… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Portal | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Portal | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Webcenter Portal | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Pendiente de análisis | Alta (7.3) | 0.14% | — | Dell Alienware Command CenterAI | 18/8/2026 | 20/8/2026 | Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Pendiente de análisis | Media (6) | 0.10% | — | Dell Alienware Command CenterAI | 18/8/2026 | 20/8/2026 | Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service and Elevation of Privileges. | |
| Aplazada | Media (4.8) | 0.63% | — | Outsystems Service CenterAI | 17/8/2026 | 28/8/2026 | OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to… | |
| Analizada | Crítica (9.4) | 2.8% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account. | |
| Analizada | Crítica (9.4) | 9.9% | 💥 Exploit | Tenable Security Center | 14/8/2026 | 19/8/2026 | An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system. | |
| Analizada | Alta (7.1) | 0.32% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database. | |
| Analizada | Alta (8.7) | 1.6% | 💥 PoC | Tenable Security Center | 14/8/2026 | 19/8/2026 | An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue. | |
| Analizada | Media (5.3) | 0.30% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope. | |
| Analizada | Media (6) | 0.26% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation. | |
| Analizada | Alta (8.5) | 0.19% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction. | |
| Analizada | Media (6.9) | 0.39% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials. | |
| Analizada | Alta (8.6) | 0.39% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management. | |
| Analizada | Alta (8.6) | 2.1% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered. | |
| Analizada | Crítica (9.4) | 1.9% | 💥 Exploit | Tenable Security Center | 14/8/2026 | 19/8/2026 | A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution… | |
| Aplazada | Media (5.5) | 0.56% | — | Alldatacenter Xxl-rpcAIAlldataAI | 14/8/2026 | 18/8/2026 | A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and… | |
| Aplazada | Media (6.5) | 0.33% | — | Piraeus Bank Secure Card Gateway FOR Epay PaycenterAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions. | |
| En análisis | Alta (8.9) | 0.45% | — | Intel Data Center Attestation PrimitivesAI | 11/8/2026 | 12/8/2026 | Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via network access when… | |
| En análisis | Media (4.3) | 0.13% | — | Intel Software Guard Extensions Data Center Attestation PrimitivesAI | 11/8/2026 | 29/9/2026 | Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur… | |
| Pendiente de análisis | Alta (7.3) | 0.15% | — | Siemens Simcenter FemapAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. | |
| Pendiente de análisis | Alta (7.3) | 0.15% | — | Siemens Simcenter FemapAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. |