Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
21.062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.46% | — | Oracle E-business SuiteAIOracle Applications DBAAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA. Successful attacks of this… | |
| Aplazada | Alta (8.2) | 0.28% | — | Oracle Siebel CRM Cloud ApplicationsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. While the… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Siebel CRM Cloud ApplicationsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful… | |
| Aplazada | Alta (7.9) | 0.16% | — | Oracle Siebel CRM Cloud ApplicationsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to… | |
| Pendiente de análisis | Alta (7.2) | 0.46% | — | Oracle Siebel Apps - MarketingAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Pendiente de análisis | Media (6.5) | 0.34% | — | Oracle WEB Applications Desktop IntegratorAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications… | |
| Pendiente de análisis | Alta (8.2) | 0.31% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Application… | |
| Pendiente de análisis | Alta (8.2) | 0.42% | — | Oracle Mobile Application ServerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application… | |
| Aplazada | Alta (7.5) | 0.39% | — | Oracle Applications ManagerAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.… | |
| Aplazada | Alta (7.1) | 0.29% | — | Oracle Applications FrameworkAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Aplazada | Crítica (9.1) | 0.47% | — | Oracle Siebel Apps - Financial ServicesAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Financial Services.… | |
| Aplazada | Alta (7.5) | 0.42% | — | Oracle Application Object LibraryAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful… | |
| Aplazada | Crítica (9.1) | 0.31% | — | Oracle Application Testing SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. While the vulnerability is in… | |
| Aplazada | Alta (8.7) | 0.32% | — | Oracle Siebel Apps - Customer Order ManagementAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Customer Order… | |
| Aplazada | Alta (8.7) | 0.32% | — | Oracle Siebel Apps - Customer Order ManagementAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Customer Order… | |
| Aplazada | Alta (8.1) | 0.36% | — | Oracle Siebel Apps Life SciencesAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: eDetailing). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Life Sciences. Successful attacks require… | |
| Aplazada | Alta (7.5) | 0.39% | — | Oracle Applications ManagerAIOracle E-business SuiteAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Bookstackapp BookstackAI | 15/9/2026 | 16/9/2026 | BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers can authenticate at one enabled social… | |
| Pendiente de análisis | Media (4.8) | 0.15% | — | Lfprojects ApptainerAI | 15/9/2026 | 25/9/2026 | Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so an allowed path such as /data/safe also authorizes a sibling path such as /data/safe-but-unsafe. A local user can consequently… | |
| Pendiente de análisis | Media (4.3) | 0.40% | — | Plone App.textfieldAI | 15/9/2026 | 30/9/2026 | plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on the release line, RichTextValue.output returns an unsanitized stored RichText value when mimeType equals outputMimeType, including values that claim… | |
| Pendiente de análisis | Crítica (9.4) | 0.20% | 💥 PoC | Apple MacosAIDocker DesktopAI | 15/9/2026 | 16/9/2026 | On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host… | |
| Pendiente de análisis | Alta (7.3) | 0.13% | — | Redhat Leapp-repositoryAI | 15/9/2026 | 16/9/2026 | A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that… | |
| Aplazada | Media (5.3) | 0.45% | — | Governikus AusweisappAI | 15/9/2026 | 16/9/2026 | A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The attack can be launched remotely. Upgrading to version 2.5.5 is able to address… | |
| Analizada | Alta (7.8) | 0.15% | — | Apple Macos | 14/9/2026 | 15/9/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges. | |
| Analizada | Media (5.5) | 0.14% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 14/9/2026 | 16/9/2026 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to delete credentials stored in Keychain. |