Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.45% | — | ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI | 21/9/2026 | 30/9/2026 | A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /authorize of the component HTTP Request Handler. Executing a manipulation of the argument Success can lead to http response splitting. It is possible to launch the… | |
| Aplazada | Baja (2.1) | 0.46% | — | ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI | 21/9/2026 | 30/9/2026 | A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has… | |
| Pendiente de análisis | Alta (7.1) | 0.24% | — | Oracle Agile Engineering Data ManagementAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to… | |
| Pendiente de análisis | Alta (7.3) | 0.14% | — | Oracle Agile Engineering Data ManagementAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering… | |
| Pendiente de análisis | Alta (7.3) | 0.23% | — | Oracle Agile Engineering Data ManagementAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to… | |
| Pendiente de análisis | Alta (8.4) | 0.14% | — | Oracle Agile Engineering Data ManagementAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | Oracle Peoplesoft Enterprise FIN Engineering BrazilAI | 15/9/2026 | 17/9/2026 | Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Engineering Brazil… | |
| Pendiente de análisis | Alta (7.7) | 0.37% | — | Oracle E-business SuiteAIOracle EngineeringAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering. While the vulnerability is… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Applications Platform Engineering | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Applications Platform Engineering product of Oracle E-Business Suite (component: Valid Session). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Applications… | |
| Analizada | Media (6.4) | 0.15% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes… | |
| Analizada | Media (4.8) | 0.22% | — | Agile Engineering Data Management Product OF Oracle Supply Chain | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile… | |
| Analizada | Alta (8.2) | 0.29% | — | Agile Engineering Data Management Product OF Oracle Supply Chain | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile… | |
| Modificada | Media (6.7) | 0.18% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes… | |
| Modificada | Alta (7) | 0.13% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile… | |
| Modificada | Media (6.3) | 0.14% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile… | |
| Modificada | Alta (7.5) | 0.33% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached… | |
| Analizada | Media (6.1) | 0.27% | — | IBM Engineering Requirements Management Doors WEB Access | 30/7/2026 | 29/9/2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Engineering Requirements Management Doors WEB Access | 30/7/2026 | 1/10/2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive. | |
| Analizada | Media (6.5) | 0.42% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful… | |
| Analizada | Media (6.5) | 0.42% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful… | |
| Analizada | Media (5.3) | 0.34% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.… | |
| Analizada | Media (4.4) | 0.14% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management… | |
| Analizada | Media (6.4) | 0.26% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.… |