Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
2632 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.3) | 0.13% | — | HP Accessory WMI ProviderAIHP Docking StationAI | 24/6/2026 | 26/6/2026 | A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege and/or arbitrary code execution. HP is releasing software updates to mitigate the potential vulnerability. | |
| Analizada | Alta (8.2) | 0.22% | — | Microfocus Access Manager | 24/6/2026 | 29/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2. | |
| Analizada | Media (6.3) | 0.30% | — | Microfocus Access Manager | 24/6/2026 | 29/6/2026 | An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3. | |
| Aplazada | Alta (7.9) | 0.43% | — | Upkeeper Solutions Upkeeper Instant Privilege AccessAI | 24/6/2026 | 25/6/2026 | Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tampering-Forging. This issue affects upKeeper Instant Privilege Access: through 1.6.1. | |
| Aplazada | Media (4.3) | 0.40% | — | Equalize Digital Accessibility CheckerAI | 18/6/2026 | 18/6/2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Access Manager | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.… | |
| Analizada | Alta (7.3) | 0.31% | — | Oracle Access Manager | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Web Server Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Access Manager | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While… | |
| Analizada | Media (6.5) | 0.27% | — | Oracle Access Manager | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.… | |
| Modificada | Media (5.7) | 0.15% | — | Powerschool Employee Access Center | 16/6/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wpdataaccess WP Data AccessAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions. | |
| Aplazada | Media (6.3) | 0.26% | — | Subscriber Broken Access Control IN Classified ListingAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions. | |
| Aplazada | Alta (7.5) | 0.37% | — | Unauthenticated Broken Access Control IN User RegistrationAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions. | |
| Analizada | Alta (8.8) | 1.0% | — | Fortra Core Privileged Access Manager Server | 15/6/2026 | 28/7/2026 | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client… | |
| Analizada | Crítica (9.8) | 1.5% | — | Fortra Core Privileged Access Manager Server | 15/6/2026 | 28/7/2026 | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing. | |
| Analizada | Alta (8.7) | 0.63% | — | Paloaltonetworks Idira Privileged Access Manager Vault | 12/6/2026 | 7/7/2026 | Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized… | |
| Analizada | Media (5.9) | 0.11% | — | Paloaltonetworks Prisma Access Agent | 10/6/2026 | 23/7/2026 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS. | |
| Analizada | Media (4.4) | 0.10% | — | Paloaltonetworks Prisma Access Agent | 10/6/2026 | 23/7/2026 | A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS. | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Lenovo Accessories AND Display Manager FOR EnterpriseAI | 10/6/2026 | 17/6/2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm C-v2x 9150 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s Firmware+269 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot commands with improperly formatted input. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+269 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. | |
| Analizada | Media (6.4) | 0.06% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Cq7790 Firmware+232 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | |
| Analizada | Media (5.5) | 0.09% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 Firmware+183 | 1/6/2026 | 22/7/2026 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. | |
| Analizada | Alta (8.8) | 0.81% | — | IBM I Access Client Solutions | 1/6/2026 | 26/8/2026 | IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator. | |
| Aplazada | Alta (7.5) | 0.48% | — | Vasyltech Advanced Access ManagerAI | 1/6/2026 | 22/7/2026 | Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue affects Advanced Access Manager: from n/a through 7.1.0. |