Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.46% | — | IBM Engineering Requirements Management Doors WEB Access | 30/7/2026 | 1/10/2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive. | |
| Aplazada | Alta (7.5) | 0.36% | — | Wptravelengine WP Travel EngineAI | 30/7/2026 | 30/7/2026 | The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the… | |
| Aplazada | Crítica (9.4) | 0.85% | — | Dynamicsoft AppengineAI | 28/7/2026 | 9/9/2026 | An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication.… | |
| Aplazada | Media (6.5) | 0.37% | — | Wpmet FundengineAI | 27/7/2026 | 27/7/2026 | Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. | |
| Pendiente de análisis | Alta (8.5) | 0.57% | — | Redhat Advanced Cluster Management FOR KubernetesAIRedhat Multicluster-engineAI | 24/7/2026 | 29/9/2026 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds… | |
| Pendiente de análisis | Crítica (10) | 4.7% | — | Zohocorp Manageengine Adaudit PlusAI | 23/7/2026 | 24/7/2026 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. | |
| Aplazada | Media (4.9) | 0.19% | — | Crocoblock JetengineAI | 23/7/2026 | 23/7/2026 | Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. | |
| Analizada | Media (6.5) | 0.42% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful… | |
| Analizada | Media (6.5) | 0.42% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful… | |
| Analizada | Media (5.3) | 0.34% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.… | |
| Analizada | Media (4.4) | 0.14% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management… | |
| Analizada | Media (6.4) | 0.26% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.… | |
| Analizada | Media (6.5) | 0.15% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to… | |
| Analizada | Baja (2.8) | 0.14% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to… | |
| Analizada | Crítica (9.4) | 0.41% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.… | |
| Analizada | Baja (3.3) | 0.21% | — | Oracle Peoplesoft Enterprise FIN Engineering Argentina | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Engineering… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Communications Billing AND Revenue Management Elastic Charging Engine | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Diameter Gateway and SDK). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the… | |
| Analizada | Media (5.9) | 0.47% | — | Capstone-engine Capstone | 21/7/2026 | 30/7/2026 | Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86… | |
| Pendiente de análisis | Alta (7.1) | 1.2% | — | Zohocorp Manageengine Adselfservice PlusAI | 21/7/2026 | 21/7/2026 | Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass. | |
| Pendiente de análisis | Media (4.3) | 0.65% | — | Zohocorp Manageengine Endpoint CentralAI | 21/7/2026 | 21/7/2026 | Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability. | |
| Aplazada | Media (5.4) | 0.23% | — | Bifra Engineering Consulting LTD Q-smart Next PollAI | 20/7/2026 | 20/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects Q-smart NexT Poll: before 1.8.7. | |
| Analizada | Alta (7.5) | 0.52% | — | IBM Engineering AI HUB | 17/7/2026 | 24/7/2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs. | |
| Analizada | Media (4.3) | 0.36% | — | IBM Engineering AI HUB | 17/7/2026 | 24/7/2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs. | |
| Analizada | Crítica (9.3) | 0.57% | — | IBM Engineering AI HUB | 17/7/2026 | 24/7/2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation. | |
| Analizada | Media (5.4) | 0.30% | — | IBM Engineering AI HUB | 17/7/2026 | 24/7/2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input during web page generation. |