Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.72% | — | Ansible Community.generalAIMemcachedAIPython-memcachedAI | 9/9/2026 | 9/9/2026 | A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached… | |
| Pendiente de análisis | Media (6.8) | 0.14% | — | Activecampaign GeneralAI | 9/9/2026 | 14/9/2026 | A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An… | |
| Pendiente de análisis | Media (5.5) | 0.15% | — | Activecampaign GeneralAI | 26/8/2026 | 28/8/2026 | A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied… | |
| Analizada | Alta (7.6) | 0.32% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Alta (7.2) | 0.14% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle General Ledger executes to compromise… | |
| Analizada | Alta (7.6) | 0.32% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle General Ledger | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Alta (7.6) | 0.34% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle General Ledger. While the… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Media (5.9) | 0.27% | — | Oracle Peoplesoft Enterprise FIN General Ledger Argentina | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN General Ledger Argentina product of Oracle PeopleSoft (component: General Ledger). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN General… | |
| Analizada | Alta (7) | 0.27% | — | Oracle JD Edwards Enterpriseone General Ledger | 21/7/2026 | 6/8/2026 | Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne General Ledger.… | |
| Aplazada | Media (5.5) | 0.41% | — | Hanwang E-face General Management PlatformAI | 5/7/2026 | 6/7/2026 | A vulnerability was identified in Hanwang e-Face General Management Platform 6.3.5.4. This impacts an unknown function of the file /sysAuthStr/querySysAuthStr.do. The manipulation of the argument order leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might… | |
| Aplazada | Media (5.5) | 0.47% | — | Hanwang E-face General Management PlatformAI | 29/6/2026 | 29/6/2026 | A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle JD Edwards Enterpriseone General Ledger | 17/6/2026 | 26/6/2026 | Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise JD Edwards EnterpriseOne General Ledger. While… | |
| Aplazada | Media (4.4) | 0.31% | — | General OptionsAI | 20/5/2026 | 24/7/2026 | The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.1.0. This is due to the use of sanitize_text_field() for output escaping in the Contact Number (ad_contact_number) field — a function that strips HTML tags but does not encode double-quote characters… | |
| Pendiente de análisis | Alta (7) | 0.11% | — | AMD General-purpose Input Output ControllerAI | 15/5/2026 | 17/6/2026 | Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary code execution. | |
| Pendiente de análisis | Alta (7) | 0.39% | — | Moxa MxgeneralioAI | 8/4/2026 | 24/7/2026 | An exposed IOCTL with an insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for Moxa’s industrial x86 computers. The affected utility, MxGeneralIo, exposes IOCTL methods that permit direct read and write access to MSR and system memory. A local attacker with high privileges… | |
| Modificada | Media (5.5) | 0.14% | — | Redhat Community.general | 4/12/2025 | 17/6/2026 | A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise… | |
| Aplazada | Alta (8.7) | 0.31% | — | General Industrial Controls Lynx Plus GatewayAI | 15/11/2025 | 17/6/2026 | General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials. | |
| Aplazada | Alta (8.7) | 0.37% | — | General Industrial Controls Lynx+ GatewayAI | 15/11/2025 | 17/6/2026 | General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET requests to obtain sensitive device information. | |
| Aplazada | Crítica (9.2) | 0.63% | — | General Industrial Controls Lynx+ GatewayAI | 15/11/2025 | 17/6/2026 | General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device. | |
| Aplazada | Alta (8.8) | 0.28% | — | General Industrial Controls Lynx Plus GatewayAI | 15/11/2025 | 17/6/2026 | General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login. | |
| Analizada | Alta (7.8) | 0.34% | — | Generalcoffee Fade IN | 28/10/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .fadein file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Alta (7.8) | 0.34% | — | Generalcoffee Fade IN | 28/10/2025 | 17/6/2026 | A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .xml file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability. |