Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
3834 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 0.52% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | |
| Analizada | Crítica (10) | 0.48% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | |
| Analizada | Alta (7.8) | 0.18% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration | |
| Analizada | Media (6.1) | 0.25% | — | Jetbrains Intellij Idea | 23/7/2026 | 28/7/2026 | In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Project Intelligence | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.… | |
| Analizada | Alta (8.2) | 0.35% | — | Oracle Business Intelligence | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.6) | 0.34% | — | Oracle Business Intelligence | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Media (4.2) | 0.20% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data. | |
| Analizada | Media (4.3) | 0.25% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions. | |
| Analizada | Baja (3.7) | 0.24% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications. | |
| Analizada | Media (5.3) | 0.29% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits. | |
| Analizada | Media (4.8) | 0.22% | — | Artificial Intelligence Project Artificial Intelligence | 10/7/2026 | 16/7/2026 | Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. | |
| Analizada | Media (4.2) | 0.19% | — | Artificial Intelligence Project Artificial Intelligence | 10/7/2026 | 16/7/2026 | Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. | |
| Analizada | Baja (3.3) | 0.21% | — | Artificial Intelligence Project Artificial Intelligence | 10/7/2026 | 16/7/2026 | Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. | |
| Analizada | Media (6.1) | 0.25% | — | Artificial Intelligence Project Artificial Intelligence | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS). This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. | |
| Analizada | Crítica (9.8) | 0.60% | — | Jetbrains Intellij Idea | 10/7/2026 | 14/7/2026 | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible | |
| Aplazada | Alta (8) | 0.51% | — | WP Business Intelligence LiteAI | 10/7/2026 | 10/7/2026 | The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Analizada | Media (5.9) | 0.20% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (4.3) | 0.28% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actions due to the improper enforcement of behavioral workflow. | |
| Analizada | Media (4.3) | 0.37% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Media (6.5) | 0.36% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls and perform unauthorized actions due to client-side enforcement of sever-side security. | |
| Analizada | Media (4.3) | 0.27% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.7) | 0.41% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (6.4) | 0.26% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |