Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Crítica (10) | 0.43% | — | Microsoft Azure BillingAI | 17/9/2026 | 19/9/2026 | Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.4) | 0.32% | — | Oracle Telecommunications Billing Integrator | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Communications Billing AND Revenue Management | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform). Supported versions that are affected are 15.0.0.0.0-15.0.1.0.0 and 15.1.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Communications Billing AND Revenue Management | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: BRM Server). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Peoplesoft Enterprise FIN Billing Argentina | 21/7/2026 | 4/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN Billing Argentina product of Oracle PeopleSoft (component: Billing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Billing Argentina.… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Communications Billing AND Revenue Management Elastic Charging Engine | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Diameter Gateway and SDK). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Telecommunications Billing Integrator | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Media (5.1) | 0.41% | — | FossbillingAI | 7/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable product, FOSSBilling stores the file as `md5(<original filename>)` under the… | |
| Aplazada | Media (6.9) | 0.54% | — | FossbillingAI | 7/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endpoint is accessible without authentication. Any caller with a valid API key can retrieve all custom configuration parameters (`custom_*` fields) stored in the key's… | |
| Aplazada | Alta (7.7) | 0.31% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `ClientPasswordReset` record already exists for a client (from a previous unexpired reset request), subsequent calls to the `reset_password` guest API endpoint reuse the existing token instead of generating… | |
| Aplazada | Alta (8.5) | 0.37% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged staff account to grant arbitrary module permissions to itself through the admin API, resulting in persistent privilege escalation. A staff user that only has `staff.create_and_edit_staff` can call… | |
| Aplazada | Alta (8.6) | 0.39% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticated clients to both read and reset API key service secrets for orders that are no longer in an `active` state (e.g., `suspended`, `canceled`). The root cause is missing order-state validation in two… | |
| Aplazada | Alta (8.7) | 0.35% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unauthorized actions via admin API endpoints. The root cause is a combination of the `can_always_access` module flag (which grants all staff access to certain modules) and… | |
| Aplazada | Media (5.3) | 0.35% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Require Email Confirmation" setting is enabled, a logged-in client with an unverified email address (`email_approved = 0`) can access all client-area pages (e.g. `/client/balance`, `/client/order/list`,… | |
| Aplazada | Media (4.8) | 0.44% | — | FossbillingAI | 6/7/2026 | 8/7/2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cross-site scripting (XSS) vulnerability in the client-facing email history views of FOSSBilling. Email HTML content (`content_html`) is rendered into a JavaScript template literal using the `|raw`… | |
| Aplazada | Baja (2.3) | 0.35% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. While sibling write endpoints correctly enforce fine-grained permissions, the corresponding read endpoints have no… | |
| Aplazada | Baja (2.3) | 0.42% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IPN callbacks and credits the IPN-supplied amount (`mc_gross`) to the client's balance without validating it against the invoice total. Combined with a $0.05 floating-point… | |
| Aplazada | Media (6.9) | 0.33% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the cart checkout flow allows an authenticated client to apply a promo code beyond its configured maximum uses. By sending concurrent checkout requests before any single request completes the usage… | |
| Aplazada | Media (6.9) | 0.46% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self-registration endpoint allows any visitor to assign themselves to an arbitrary client group during sign-up. Because client groups can gate promo code… | |
| Aplazada | Alta (8.9) | 0.43% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOSSBilling's `Config::prettyPrintArrayToPHP()` method. When configuration values are updated, string values are written into `config.php` without escaping single quotes.… | |
| Aplazada | Alta (8.7) | 0.36% | — | FossbillingAI | 6/7/2026 | 8/7/2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. The session identity loaders in src/di.php (loggedin_client and loggedin_admin) only reject… | |
| Aplazada | Crítica (9.2) | 0.27% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client… | |
| Aplazada | Alta (7.7) | 0.42% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in other invoice-related endpoints, allowing an unauthenticated user with knowledge of an invoice hash to modify the payment gateway… | |
| Aplazada | Media (6.9) | 0.37% | — | FossbillingAI | 6/7/2026 | 7/7/2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Massmailer` module filter functionality. An authenticated administrator can supply crafted filter values when updating a mass email message, causing untrusted input to be… | |
| Aplazada | Media (6.9) | 0.90% | — | FossbillingAI | 26/6/2026 | 26/6/2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, which allowed unauthenticated remote users to trigger update patch routines that modify configuration files, execute… |