Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 1.1% | — | Zohocorp Manageengine OpmanagerAIZohocorp Network Configuration ManagerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability. | |
| Pendiente de análisis | Alta (7.6) | 1.5% | — | Zohocorp Manageengine OpmanagerAIZohocorp Netflow AnalyzerAIZohocorp Network Configuration ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution. | |
| Pendiente de análisis | Media (5.4) | 0.14% | — | Jenkins JOB Configuration HistoryAI | 2/9/2026 | 4/9/2026 | Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings. | |
| Pendiente de análisis | Alta (7) | 0.13% | — | Redundancy Module Configuration ToolAI | 1/9/2026 | 1/9/2026 | A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a… | |
| Aplazada | Crítica (9.3) | 0.53% | — | Ebyte Configuration UtilityAI | 31/8/2026 | 1/9/2026 | The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing… | |
| Pendiente de análisis | Alta (8.4) | 0.11% | — | Bosch Configuration ManagerAI | 23/7/2026 | 1/10/2026 | Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information. | |
| Analizada | Media (6.3) | 0.27% | — | Oracle Human Capital Management Configuration Workbench | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench.… | |
| Analizada | Alta (7.3) | 0.31% | — | Oracle Human Capital Management Configuration Workbench | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Configuration… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Human Capital Management Configuration Workbench | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HCM Configuration… | |
| Analizada | Media (6.5) | 0.39% | — | Oracle Human Capital Management Configuration Workbench | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HCM Configuration… | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Configuration Manager 2503Microsoft Configuration Manager 2509Microsoft Configuration Manager 2603 | 14/7/2026 | 30/7/2026 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (4.3) | 0.19% | — | Jenkins JOB Configuration History | 24/6/2026 | 26/6/2026 | Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers with Extended Read permission to view encrypted secret values that would otherwise be redacted. | |
| Aplazada | Baja (1.9) | 0.06% | — | Steeltoe Configuration.encryptionAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=OAEP` does not enable OAEP encryption. Due to an incorrect BouncyCastle transformation string, the… | |
| Aplazada | Media (4.7) | 0.08% | — | Steeltoe Configuration AbstractionsAIMysqlAIPostgresqlAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include TLS client credentials, the Connectors library writes those… | |
| Analizada | Media (5.3) | 0.82% | — | Apache Commons Configuration | 14/5/2026 | 17/6/2026 | Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue. | |
| Pendiente de análisis | Alta (7.1) | 0.14% | — | AMD Platform Configuration BlobAI | 16/4/2026 | 15/7/2026 | Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Analizada | Crítica (9.3) | 0.80% | — | Dragonsoft Gcb/fcb Government Financial Cybersecurity Configuration Audit Software | 17/3/2026 | 17/6/2026 | GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account. | |
| Analizada | Alta (7.5) | 0.16% | — | Hitachi Configuration ManagerHitachi OPS Center API Configuration Manager | 25/2/2026 | 17/6/2026 | Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Manager: from 8.6.1-00 before 11.0.5-00. | |
| Analizada | Media (5.2) | 0.14% | — | Hitachi Configuration ManagerHitachi Device ManagerHitachi OPS Center API Configuration Manager | 25/2/2026 | 17/6/2026 | Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before… | |
| Analizada | Alta (7.8) | 0.19% | — | Tanium Endpoint Configuration Toolset SolutionTanium Patch Endpoint Tools | 10/2/2026 | 17/6/2026 | Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools. | |
| Aplazada | Crítica (9.5) | 1.5% | — | Johnsoncontrols Metasys Application AND Data ServerAIJohnsoncontrols Metasys Extended Application AND Data ServerAIJohnsoncontrols Lcs8500AIJohnsoncontrols Nae8500AI+2 | 30/1/2026 | 17/6/2026 | Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects | |
| Aplazada | Alta (7.1) | 0.45% | — | Johnsoncontrols Istar Configuration UtilityAI | 28/1/2026 | 17/6/2026 | Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iSTAR Configuration Utility (ICU) version 6.9.7 and prior. Successful exploitation of this vulnerability could result in failure within the operating system of the machine hosting the ICU tool. | |
| Aplazada | Alta (8.5) | 0.15% | — | OKI Configuration ToolAI | 21/1/2026 | 17/6/2026 | OKI Configuration Tool 1.6.53 contains an unquoted service path vulnerability in the OKI Local Port Manager service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Common\extend3\portmgrsrv.exe' to inject malicious executables and… | |
| Analizada | Media (6.7) | 0.35% | — | Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 2503 | 11/11/2025 | 17/6/2026 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Server Configuration UtilityAIIntel Server Firmware Update UtilityAI | 11/11/2025 | 17/6/2026 | Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software and Intel(R) Server Firmware Update Utility software before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user… |