Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2571▼ 331 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

574 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.18%—Trusted Shops Easy Integration FOR WoocommerceAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.
Pendiente de análisisCrítica (9.4)0.36%—Google Cloud Application IntegrationAI28/9/202630/9/2026
A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing…
Pendiente de análisisAlta (8.3)0.32%—Google Cloud Application IntegrationAI28/9/202629/9/2026
A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path. This vulnerability was patched on 30 June…
Pendiente de análisisCrítica (9.4)0.24%—Google Cloud Application IntegrationAI28/9/202629/9/2026
An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud user to execute arbitrary internal RPCs from inside Google's production network under a privileged identity using an…
Pendiente de análisisMedia (5.5)0.13%—Dell Command Integration Suite FOR System CenterAI21/9/202622/9/2026
Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
Pendiente de análisisMedia (4.2)0.11%—Jenkins Bitbucket Server Integration PluginAI16/9/202618/9/2026
The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack the OAuth flow and obtain an access token on behalf of the victim.
AplazadaAlta (7.5)0.42%—Oracle Siebel CRM IntegrationAI15/9/202621/9/2026
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this…
AplazadaMedia (6.8)0.21%—Oracle HelidonAIOracle Helidon-integrations-neo4jAI15/9/202618/9/2026
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-integrations-neo4j). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware…
AplazadaAlta (8.1)0.27%—Oracle Siebel CRM IntegrationAI15/9/202618/9/2026
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe). Supported versions that are affected are 23.6-26.7. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the…
Pendiente de análisisMedia (6.6)0.48%—Softing OPC UA C++ SDKAISofting Secure Integration ServerAI14/9/202622/9/2026
An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects.
Pendiente de análisisAlta (8.8)0.44%—Pentaho Data IntegrationAI11/9/202618/9/2026
The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.
Pendiente de análisisAlta (7.8)0.19%—IBM Webmethods Integration ServerAI10/9/202611/9/2026
IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
AplazadaMedia (6.5)0.27%—Onlyoffice Ownclouds IntegrationAIOwncloudsAI8/9/202610/9/2026
A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can…
Pendiente de análisisMedia (6.5)0.25%—SAP Manufacturing Integration AND IntelligenceAI8/9/20268/9/2026
Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful…
Pendiente de análisisAlta (8.5)0.38%—SAP Integration SuiteAI8/9/20268/9/2026
SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read…
Pendiente de análisisBaja (2.2)0.34%—SAP Process IntegrationAI8/9/20268/9/2026
SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with…
AnalizadaMedia (6.5)0.29%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/202610/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
AnalizadaMedia (6.5)0.29%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
AnalizadaMedia (5.5)0.09%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/202610/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.
AnalizadaMedia (5.5)0.10%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.
AnalizadaMedia (5.5)0.11%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20268/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials.
AnalizadaMedia (5.7)0.22%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an authenticated user to cause a denial-of-service condition due to improper validation of XML entities.
AnalizadaAlta (7.5)0.55%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop.
AnalizadaMedia (5.5)0.11%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials.
AnalizadaAlta (7.7)0.38%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20268/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.