Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
5030 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.32% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Data… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data… | |
| Analizada | Alta (7.5) | 0.47% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Hyperion Data… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Hyperion Data… | |
| Analizada | Alta (7.6) | 0.34% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data… | |
| Analizada | Alta (7.6) | 0.15% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Hyperion Data… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Hyperion Data Relationship Management | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data… | |
| Aplazada | Media (6.5) | 0.36% | — | Oracle Database ServerAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Net Services. Successful attacks require human interaction from a… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Atlassian Confluence Data CenterAI | 15/9/2026 | 16/9/2026 | This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be… | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Atlassian Jira Service Management Data CenterAI | 15/9/2026 | 17/9/2026 | This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. * Jira Service Management Data Center 11.3: Upgrade to a release greater than or equal to 11.3.11 | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Atlassian Confluence Data CenterAI | 15/9/2026 | 17/9/2026 | This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain… | |
| Pendiente de análisis | Alta (8.2) | 0.21% | — | IBM Cloud PAK FOR Data SystemAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols. | |
| Aplazada | Crítica (9.8) | 0.78% | — | ResdataAI | 14/9/2026 | 30/9/2026 | resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRDECL files in lib/resdata/rd_kw_grdecl.cpp and lib/resdata/rd_grid.cpp. Malformed… | |
| Analizada | Alta (8.8) | 0.43% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property. | |
| Analizada | Alta (8.8) | 0.93% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection. | |
| Analizada | Media (6.5) | 0.34% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | |
| Analizada | Alta (8.8) | 0.55% | — | IBM Datastage ON Cloud PAK FOR Data | 14/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine. |