Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.2) | 0.13% | — | Oracle Planning AND Budgeting Cloud ServiceAIOracle HyperionAIOracle EPM AgentAI | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Planning and Budgeting Cloud Service… | |
| Analizada | Media (4.2) | 0.15% | — | Oracle Planning AND Budgeting Cloud Service | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Planning and Budgeting Cloud Service… | |
| Aplazada | Alta (8.5) | 0.31% | — | Lexmark Cloud ServicesAI | 19/8/2025 | 17/6/2026 | A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization | |
| Aplazada | Crítica (9.4) | 0.40% | — | Growatt Cloud ServiceAI | 19/7/2025 | 17/6/2026 | An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account. | |
| Analizada | Alta (7.8) | 0.33% | — | Ivanti Cloud Services Appliance | 13/5/2025 | 17/6/2026 | Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges. | |
| Aplazada | Baja (3.5) | 0.26% | — | Whatsapp Cloud ServiceAI | 20/3/2025 | 17/6/2026 | The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with BIGPRETZEL. | |
| Analizada | Alta (7.2) | 22% | — | Ivanti Cloud Services Appliance | 11/2/2025 | 17/6/2026 | OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Media (5.3) | 1.2% | — | Ivanti Cloud Services Appliance | 11/2/2025 | 17/6/2026 | Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality. | |
| Analizada | Alta (7.2) | 23% | — | Ivanti Cloud Services Appliance | 10/12/2024 | 17/6/2026 | SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements. | |
| Analizada | Alta (7.2) | 7.7% | — | Ivanti Cloud Services Appliance | 10/12/2024 | 17/6/2026 | Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Crítica (9.8) | 4.9% | — | Ivanti Cloud Services Appliance | 10/12/2024 | 17/6/2026 | An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access | |
| Analizada | Alta (7.2) | 16% | — | Ivanti Endpoint Manager Cloud Services Appliance | 8/10/2024 | 17/6/2026 | Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions. | |
| Analizada | Alta (7.2) | 60% | ⚠ Explotación activa | Ivanti Endpoint Manager Cloud Services Appliance | 8/10/2024 | 17/6/2026 | An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution. | |
| Analizada | Alta (7.2) | 44% | ⚠ Explotación activa | Ivanti Endpoint Manager Cloud Services Appliance | 8/10/2024 | 1/10/2026 | SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements. | |
| Analizada | Crítica (9.1) | 99% | ⚠ Explotación activa | Ivanti Endpoint Manager Cloud Services Appliance | 19/9/2024 | 17/6/2026 | Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. | |
| Analizada | Alta (7.2) | 89% | ⚠ Explotación activa | Ivanti Cloud Services Appliance | 10/9/2024 | 17/6/2026 | An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability. | |
| Aplazada | Crítica (9.4) | 0.50% | — | Ewelink Cloud ServiceAI | 31/7/2024 | 17/6/2026 | When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information. | |
| Modificada | Media (5.4) | 0.60% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/12/2023 | 17/6/2026 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | |
| Modificada | Media (5.4) | 0.60% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/12/2023 | 17/6/2026 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page… | |
| Modificada | Media (5.4) | 0.60% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/12/2023 | 17/6/2026 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page… | |
| Modificada | Media (5.4) | 0.60% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/12/2023 | 17/6/2026 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page… | |
| Modificada | Media (5.4) | 0.60% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/12/2023 | 17/6/2026 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page… | |
| Modificada | Media (5.4) | 0.60% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/12/2023 | 17/6/2026 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page… | |
| Modificada | Media (5.4) | 0.60% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/12/2023 | 17/6/2026 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page… | |
| Modificada | Media (5.4) | 0.60% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/12/2023 | 17/6/2026 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page… |