Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

2649 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.46%—IBM Engineering Requirements Management Doors WEB Access30/7/20261/10/2026
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.
AplazadaAlta (7.5)0.36%—Wptravelengine WP Travel EngineAI30/7/202630/7/2026
The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the…
AplazadaCrítica (9.4)0.85%—Dynamicsoft AppengineAI28/7/20269/9/2026
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication.…
AplazadaMedia (6.5)0.37%—Wpmet FundengineAI27/7/202627/7/2026
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
Pendiente de análisisAlta (8.5)0.57%—Redhat Advanced Cluster Management FOR KubernetesAIRedhat Multicluster-engineAI24/7/202629/9/2026
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds…
Pendiente de análisisCrítica (10)4.7%—Zohocorp Manageengine Adaudit PlusAI23/7/202624/7/2026
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
AplazadaMedia (4.9)0.19%—Crocoblock JetengineAI23/7/202623/7/2026
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
AnalizadaMedia (6.5)0.42%—Oracle Agile Engineering Data Management21/7/202628/7/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful…
AnalizadaMedia (6.5)0.42%—Oracle Agile Engineering Data Management21/7/202628/7/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful…
AnalizadaMedia (5.3)0.34%—Oracle Agile Engineering Data Management21/7/202628/7/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.…
AnalizadaMedia (4.4)0.14%—Oracle Agile Engineering Data Management21/7/202628/7/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management…
AnalizadaMedia (6.4)0.26%—Oracle Agile Engineering Data Management21/7/202629/7/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.…
AnalizadaMedia (6.5)0.15%—Oracle Agile Engineering Data Management21/7/202629/7/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to…
AnalizadaBaja (2.8)0.14%—Oracle Agile Engineering Data Management21/7/202628/7/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to…
AnalizadaCrítica (9.4)0.41%—Oracle Agile Engineering Data Management21/7/202629/7/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.…
AnalizadaBaja (3.3)0.21%—Oracle Peoplesoft Enterprise FIN Engineering Argentina21/7/20266/8/2026
Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Engineering…
AnalizadaAlta (7.8)0.16%—Oracle Communications Billing AND Revenue Management Elastic Charging Engine21/7/202619/8/2026
Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Diameter Gateway and SDK). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the…
AnalizadaMedia (5.9)0.47%—Capstone-engine Capstone21/7/202630/7/2026
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86…
Pendiente de análisisAlta (7.1)1.2%—Zohocorp Manageengine Adselfservice PlusAI21/7/202621/7/2026
Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
Pendiente de análisisMedia (4.3)0.65%—Zohocorp Manageengine Endpoint CentralAI21/7/202621/7/2026
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
AplazadaMedia (5.4)0.23%—Bifra Engineering Consulting LTD Q-smart Next PollAI20/7/202620/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects Q-smart NexT Poll: before 1.8.7.
AnalizadaAlta (7.5)0.52%—IBM Engineering AI HUB17/7/202624/7/2026
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.
AnalizadaMedia (4.3)0.36%—IBM Engineering AI HUB17/7/202624/7/2026
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs.
AnalizadaCrítica (9.3)0.57%—IBM Engineering AI HUB17/7/202624/7/2026
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.
AnalizadaMedia (5.4)0.30%—IBM Engineering AI HUB17/7/202624/7/2026
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input during web page generation.