Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
3834 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.43% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to cause a temporary denial using a specially crafted HTTP request due to improper allocation of resource throttling. | |
| Modificada | Media (5.9) | 0.20% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Pendiente de análisis | Crítica (9.3) | 1.3% | 💥 PoC | Nvidia Spatial Intelligence LABAI | 17/6/2026 | 14/7/2026 | NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can… | |
| Modificada | Alta (7.5) | 0.33% | — | Oracle HR Intelligence | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HR Intelligence. Successful… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle HR Intelligence | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HR Intelligence. Successful… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle HR Intelligence | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HR Intelligence. Successful… | |
| Aplazada | Baja (2) | 0.37% | — | Intelbras Invu 7016 FTAI | 15/6/2026 | 24/7/2026 | A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/syslog/ of the component Web Interface. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be… | |
| Aplazada | Baja (1.9) | 0.21% | — | Intelliants Subrion CMSAI | 15/6/2026 | 24/7/2026 | A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functionality of the component Blocks Endpoint. Such manipulation of the argument CSS class name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Aplazada | Crítica (9.8) | 0.21% | — | Shenzhen Kangda XIN Intelligent Network Technology Dr300AI | 9/6/2026 | 23/7/2026 | Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has telnet enabled by default on WAN and LAN interfaces. These vulnerabilities allow attackers to read and write to memory, modify firmware stored in flash, inspect active… | |
| Pendiente de análisis | Media (4.3) | 0.15% | — | SAP Business Objects Business Intelligence PlatformAI | 9/6/2026 | 23/7/2026 | SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by authenticated users, resulting in an email spoofing vulnerability.This vulnerability has a low impact on integrity and does not affect the confidentiality and availability of the application. | |
| Aplazada | Media (6.3) | 0.22% | 💥 PoC | Arket Globe Document IntelligenceAI | 4/6/2026 | 22/7/2026 | Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper sanitization of user input in text fields when creating a new document. Specifically, when an authenticated attacker submits data containing JavaScript code within these… | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm C-v2x 9150 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s Firmware+269 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot commands with improperly formatted input. | |
| Analizada | Alta (8.2) | 0.07% | 💥 PoC | Qualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+242 | 1/6/2026 | 22/7/2026 | Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+269 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. | |
| Analizada | Media (6.4) | 0.06% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Cq7790 Firmware+232 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | |
| Analizada | Baja (3.3) | 0.14% | — | Jetbrains Intellij Idea | 29/5/2026 | 22/7/2026 | In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible | |
| Analizada | Alta (7.8) | 0.18% | — | Jetbrains Intellij Idea | 29/5/2026 | 22/7/2026 | In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin | |
| Analizada | Alta (8.8) | 0.51% | — | Jetbrains Intellij Idea | 29/5/2026 | 22/7/2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account | |
| Analizada | Alta (7.8) | 0.68% | — | Jetbrains Intellij Idea | 29/5/2026 | 22/7/2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion | |
| Aplazada | Media (4.8) | 0.18% | — | ITP Technology ITS Intelligent Scada SystemAI | 29/5/2026 | 21/7/2026 | ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load. | |
| Aplazada | Media (4.8) | 0.18% | — | ITP Technology ITS Intelligent Scada SystemAI | 29/5/2026 | 21/7/2026 | ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load. | |
| Analizada | Media (6.2) | 0.42% | — | Flowintel | 28/5/2026 | 17/6/2026 | FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the application server to issue an HTTP HEAD request to an attacker-specified destination. Due… | |
| Analizada | Alta (8.2) | 0.17% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 23/7/2026 | Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing… | |
| Analizada | Media (5.5) | 0.07% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 5/10/2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | |
| Analizada | Media (5.5) | 0.10% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 5/10/2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information. |