Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
3798 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.27% | — | Oracle Applications Manager | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Application Object Library | 21/7/2026 | 5/8/2026 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Application Testing Suite | 21/7/2026 | 24/7/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Application Testing Suite | 21/7/2026 | 24/7/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Application Testing Suite | 21/7/2026 | 24/7/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Application Testing Suite | 21/7/2026 | 24/7/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized access… | |
| Modificada | Media (5.4) | 0.39% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 17/7/2026 | 16/9/2026 | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that… | |
| Modificada | Baja (2.7) | 0.35% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 16/7/2026 | 16/9/2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to… | |
| Analizada | Media (4.3) | 0.36% | — | Spaceapplications Yamcs | 16/7/2026 | 20/7/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omitted specific packet names: with an empty name list the… | |
| Analizada | Crítica (9.1) | 1.1% | — | Spaceapplications Yamcs | 16/7/2026 | 20/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase… | |
| Analizada | Crítica (9.8) | 0.98% | — | Spaceapplications Yamcs | 16/7/2026 | 20/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a ClassFilter, so a user with the ChangeMissionDatabase privilege could… | |
| Analizada | Crítica (9.1) | 1.1% | — | Spaceapplications Yamcs | 16/7/2026 | 17/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino compiler without… | |
| Analizada | Crítica (9.8) | 2.1% | 💥 Exploit | Spaceapplications Yamcs | 16/7/2026 | 17/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform… | |
| Modificada | Media (4.3) | 1.1% | 💥 Exploit | Spaceapplications Yamcs | 16/7/2026 | 18/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one with low or no… | |
| Aplazada | Crítica (9.3) | 0.52% | — | SAP Cloud Application Programming ModelAICap-js Db-serviceAISqliteAISupabase PostgresAI | 15/7/2026 | 15/7/2026 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were… | |
| Analizada | Alta (7.8) | 0.17% | — | Adobe Creative Cloud Desktop Application | 14/7/2026 | 28/8/2026 | Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is… | |
| Analizada | Alta (7.8) | 0.23% | — | Adobe Creative Cloud Desktop Application | 14/7/2026 | 28/8/2026 | Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Pendiente de análisis | Media (4.7) | 0.23% | — | SAP Netweaver Application Server AbapAI | 14/7/2026 | 14/7/2026 | Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeaver Application Server ABAP reflects unsanitized input into the HTTP response which allows an attacker to inject and execute arbitrary JavaScript code under certain conditions. Successful exploitation… | |
| Pendiente de análisis | Alta (8.2) | 0.36% | — | SAP Netweaver Application Server JavaAI | 14/7/2026 | 14/7/2026 | SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the… | |
| Pendiente de análisis | Crítica (9.9) | 0.56% | — | SAP Netweaver Application Server AbapAI | 14/7/2026 | 29/7/2026 | SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the… | |
| Analizada | Alta (7.5) | 0.36% | — | UI Unifi Network Application | 2/7/2026 | 6/7/2026 | A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed. | |
| Analizada | Alta (8.1) | 0.39% | — | UI Unifi Talk Application | 2/7/2026 | 9/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application. | |
| Analizada | Alta (8.3) | 0.37% | — | UI Unifi Network Application | 2/7/2026 | 6/7/2026 | A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. | |
| Analizada | Alta (8.8) | 0.47% | — | UI Unifi Network Application | 2/7/2026 | 6/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. | |
| Analizada | Alta (7.5) | 0.37% | — | UI Unifi Talk Application | 2/7/2026 | 9/7/2026 | A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API endpoints. |