Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

2493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.3)0.82%—Microsoft Edge Chromium1/7/20263/7/2026
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Pendiente de análisisAlta (8.2)0.43%—Poly CCXAIPoly TrioAIPoly Edge EAI1/7/20262/7/2026
The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
AplazadaMedia (6.9)0.46%—CapgoAISupabase Edge FunctionsAI22/6/202623/6/2026
Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /private/role_bindings/:org_id endpoint, unlike the POST and DELETE role_bindings routes, so unauthenticated requests reach the handler instead of being rejected at the middleware layer. The handler…
ModificadaMedia (5.4)0.52%—Microsoft Edge Chromium19/6/20261/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)0.33%—Oracle Subledger Accounting17/6/202618/6/2026
Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Subledger Accounting.…
AnalizadaAlta (7.5)0.33%—Oracle Subledger Accounting17/6/202618/6/2026
Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Subledger Accounting.…
AnalizadaCrítica (9.9)0.43%—Oracle JD Edwards Enterpriseone General Ledger17/6/202626/6/2026
Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise JD Edwards EnterpriseOne General Ledger. While…
AplazadaAlta (7.2)0.40%—IEI Integration Corp Ivec Virtualization Edge ComputerAI12/6/202617/6/2026
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this vulnerability to delete arbitrary system files or directories, resulting in data destruction or service disruption.
AplazadaAlta (8.6)0.95%—IEI Integration Corp Ivec Virtualization Edge ComputerAI12/6/202617/6/2026
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, allowing privileged remote attackers to inject arbitrary OS commands and execute them on the device.
AplazadaMedia (6.9)0.41%—IEI Integration Corp Ivec-iei Virtualization Edge ComputerAI12/6/202617/6/2026
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, allowing privileged remote attackers to access files outside the intended directory scope.
AnalizadaCrítica (9.1)0.73%—Paloaltonetworks Idira Secrets Manager Edge11/6/202622/6/2026
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal…
AnalizadaCrítica (9.8)0.97%—Microsoft Azure Stack Edge9/6/202623/7/2026
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.4)0.83%—Microsoft Azure Stack Edge9/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.
AplazadaMedia (5.5)0.15%—Hyperledger Fabric-chaincode-javaAI8/6/202623/7/2026
fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An…
AnalizadaAlta (7.5)0.47%—Synology C2 Identity Edge Server27/5/20267/10/2026
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.
AplazadaMedia (4.1)0.14%—Ledger Bitcoin APPAI20/5/202623/7/2026
Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: fragment. Attackers can craft malicious miniscript policies that cause the device…
AplazadaMedia (5.1)0.21%—Ledger Nano XAILedger FlexAILedger StaxAI19/5/202624/7/2026
Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. An attacker can provide a crafted reset_handler address pointing to invalid memory or attacker-controlled code to cause…
AplazadaMedia (6.9)0.26%—Ledgerhq Hw-app-ethAILedger LiveAI19/5/202624/7/2026
Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting incorrect hexadecimal field parsing when values contain an odd number of characters. Attackers can obtain signatures on…
ModificadaCrítica (9.8)1.0%—Microsoft Edge Chromium18/5/202617/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaMedia (6.1)0.41%—Microsoft Edge Chromium18/5/202617/6/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
AnalizadaMedia (5.4)0.41%—Microsoft Edge Chromium18/5/202617/6/2026
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
AplazadaAlta (8.5)0.19%—Ipknowledge Musetheque V4AIIpknowledge V4l1AI15/5/202617/6/2026
Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected product, unexpected operations may be done.
AplazadaMedia (4.8)0.13%—Ipknowledge Musetheque V4AI15/5/202617/6/2026
Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script may be executed on a user's web browser when viewing the administration page showing the information of the file.
AnalizadaAlta (7.1)0.28%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202617/6/2026
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information. Note: Software versions which have reached End of Technical Support (EoTS) are…
En análisisAlta (8.5)0.58%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202618/6/2026
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.