Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
4639 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.27% | — | Oracle Retail Xstore Point OF Service | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of… | |
| Analizada | Baja (3.3) | 0.14% | — | Oracle Retail Xstore Point OF Service | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Turkmesh Communication Services INC Turkhotspot 5651 LoglamaAI | 21/7/2026 | 21/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This issue affects Turkhotspot 5651 Loglama: from 5.1.2 before 5.1.3. | |
| Pendiente de análisis | Alta (7.1) | 1.2% | — | Zohocorp Manageengine Adselfservice PlusAI | 21/7/2026 | 21/7/2026 | Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass. | |
| Aplazada | Media (6.5) | 0.36% | — | GIS Informatics Engineering Consulting Laboratory RND AND Software Services Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026. | |
| Aplazada | Crítica (9.3) | 0.52% | — | SAP Cloud Application Programming ModelAICap-js Db-serviceAISqliteAISupabase PostgresAI | 15/7/2026 | 15/7/2026 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were… | |
| Analizada | Media (5.5) | 0.50% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 15/7/2026 | 25/9/2026 | This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system. | |
| Analizada | Alta (8.7) | 0.57% | — | F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Next Service Proxy FOR Kubernetes | 15/7/2026 | 6/8/2026 | When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a… | |
| Aplazada | Alta (8.5) | 0.11% | — | Asus Aura Wallpaper ServiceAI | 15/7/2026 | 15/7/2026 | Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this… | |
| Aplazada | Media (6.5) | 0.52% | — | Caxperts Universalplantviewer Webservices ServerAI | 14/7/2026 | 15/7/2026 | Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver. | |
| Pendiente de análisis | Alta (8.8) | 0.15% | — | Rockwellautomation Factorytalk Services PlatformAI | 14/7/2026 | 14/7/2026 | A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and… | |
| Pendiente de análisis | Crítica (9.5) | 1.4% | 💥 Exploit | Servicenow AI PlatformAI | 13/7/2026 | 14/7/2026 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to… | |
| Aplazada | Alta (7.1) | 0.25% | — | Room 34 Creative Services LLC ICS CalendarAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Reflected XSS.This issue affects ICS Calendar: from n/a through <= 12.1.1. | |
| Aplazada | Crítica (9.5) | 0.26% | — | Evbee ServiceAI | 13/7/2026 | 13/7/2026 | The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path between the app and EVbee server to intercept and manipulate the communication between the app and server. The traffic is weakly encrypted… | |
| Aplazada | Media (6.8) | 0.16% | — | Samsung SemclipboardserviceAI | 10/7/2026 | 14/7/2026 | Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege. | |
| Aplazada | Media (6.7) | 0.17% | — | Samsung Wallpaper ServiceAI | 10/7/2026 | 11/7/2026 | Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system server privilege. | |
| Aplazada | Media (6.9) | 0.15% | — | Samsung SeagentserviceAI | 10/7/2026 | 10/7/2026 | Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information. | |
| Aplazada | Media (6.9) | 0.13% | — | Samsung IafdserviceAI | 10/7/2026 | 10/7/2026 | Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs. | |
| Pendiente de análisis | Media (6.9) | 0.47% | — | California Courts Hearing Reminder ServiceAI | 9/7/2026 | 21/7/2026 | The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder records containing potentially sensitive information without authentication. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Inrove Software AND Internet Services BieticaretAI | 9/7/2026 | 9/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57. | |
| Aplazada | Media (6.1) | 0.25% | — | Inrove Software AND Internet Services BietacardAI | 9/7/2026 | 9/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS. This issue affects BiEticaret: before v3.3.57. | |
| Aplazada | Crítica (9.8) | 0.93% | 💥 PoC | MifiserviceAIUz801 V2.1 4G LTE RouterAI | 8/7/2026 | 9/7/2026 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint in MifiService.apk | |
| Aplazada | Alta (8.1) | 0.48% | — | Caxperts UpvwebservicesAICaxperts Udith PortalAI | 8/7/2026 | 9/7/2026 | In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license. | |
| Pendiente de análisis | Media (6.3) | 0.28% | — | Trustyai-service-operatorAITrustyai GorchAI | 8/7/2026 | 31/8/2026 | A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the kube-rbac-proxy and… | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | Trustyai Service OperatorAIGorchAINemoguardrailsAI | 8/7/2026 | 31/8/2026 | A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the… |