Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.45% | — | Hyperledger Fabric CAAI | 15/9/2026 | 30/9/2026 | Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts the username from HTTP Basic authentication into the LDAP uid search UserFilter without escaping LDAP metacharacters. An unauthenticated… | |
| Aplazada | Media (5.5) | 0.51% | — | Hyperledger FireflyAI | 31/8/2026 | 1/9/2026 | A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery. Remote exploitation of… | |
| Analizada | Alta (7.6) | 0.32% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Alta (7.2) | 0.14% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle General Ledger executes to compromise… | |
| Analizada | Alta (7.6) | 0.32% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle General Ledger | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Alta (7.6) | 0.34% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle General Ledger. While the… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle General Ledger | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks… | |
| Analizada | Crítica (9.1) | 0.93% | — | Microsoft Azure Confidential Ledger | 7/8/2026 | 7/8/2026 | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | |
| Analizada | Media (5.9) | 0.27% | — | Oracle Peoplesoft Enterprise FIN General Ledger Argentina | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN General Ledger Argentina product of Oracle PeopleSoft (component: General Ledger). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN General… | |
| Analizada | Alta (7) | 0.27% | — | Oracle JD Edwards Enterpriseone General Ledger | 21/7/2026 | 6/8/2026 | Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne General Ledger.… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Subledger Accounting | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Subledger Accounting.… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Subledger Accounting | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Subledger Accounting.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle JD Edwards Enterpriseone General Ledger | 17/6/2026 | 26/6/2026 | Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise JD Edwards EnterpriseOne General Ledger. While… | |
| Aplazada | Media (5.5) | 0.15% | — | Hyperledger Fabric-chaincode-javaAI | 8/6/2026 | 23/7/2026 | fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An… | |
| Aplazada | Media (4.1) | 0.14% | — | Ledger Bitcoin APPAI | 20/5/2026 | 23/7/2026 | Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: fragment. Attackers can craft malicious miniscript policies that cause the device… | |
| Aplazada | Media (5.1) | 0.21% | — | Ledger Nano XAILedger FlexAILedger StaxAI | 19/5/2026 | 24/7/2026 | Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. An attacker can provide a crafted reset_handler address pointing to invalid memory or attacker-controlled code to cause… | |
| Aplazada | Media (6.9) | 0.26% | — | Ledgerhq Hw-app-ethAILedger LiveAI | 19/5/2026 | 24/7/2026 | Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting incorrect hexadecimal field parsing when values contain an odd number of characters. Attackers can obtain signatures on… | |
| Analizada | Crítica (9.3) | 0.63% | — | Hyperledger Fabric | 7/5/2026 | 25/8/2026 | Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays without configuring an… | |
| Aplazada | Alta (8.7) | 0.28% | — | Hyperledger BesuAIHyperledger Besu-nativeAI | 7/5/2025 | 17/6/2026 | Besu Native contains scripts and tooling that is used to build and package the native libraries used by the Ethereum client Hyperledger Besu. Besu 24.7.1 through 25.2.2, corresponding to besu-native versions 0.9.0 through 1.2.1, have a potential consensus bug for the precompiles ALTBN128_ADD (0x06), ALTBN128_MUL… | |
| Modificada | Media (5.3) | 0.59% | — | Hyperledger Fabric | 25/8/2024 | 17/6/2026 | Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window. | |
| Modificada | Alta (7.5) | 0.27% | — | Ledgersmb | 2/2/2024 | 17/6/2026 | LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin into clicking on a link which automatically submits a request to setup.pl without the admin's consent. This request can be used to create a new user… | |
| Modificada | Media (6.5) | 0.32% | — | Hyperledger Ursa | 16/1/2024 | 17/6/2026 | Ursa is a cryptographic library for use with blockchains. The revocation scheme that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model. Notably, a malicious verifier may be able to generate a unique identifier for… | |
| Modificada | Alta (8.1) | 0.28% | — | Hyperledger Ursa | 16/1/2024 | 17/6/2026 | Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model, allowing a malicious holder of a revoked credential to generate a valid… |