Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.33% | — | Oracle Operations Intelligence | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Operations Intelligence product of Oracle E-Business Suite (component: Daily Business Intelligence). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Operations… | |
| Analizada | Media (6.3) | 0.26% | — | IBM Operations Analytics - LOG Analysis | 30/7/2026 | 1/10/2026 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (5.4) | 0.32% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud Platform | 8/6/2026 | 23/7/2026 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations. | |
| Analizada | Alta (8) | 0.42% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud PlatformVmware Vsphere | 8/6/2026 | 23/7/2026 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations. | |
| Analizada | Media (5.4) | 0.32% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud PlatformVmware Vsphere | 8/6/2026 | 23/7/2026 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations. | |
| Analizada | Alta (7.8) | 0.18% | — | IBM Operations Analytics LOG Analysis | 27/5/2026 | 17/6/2026 | IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication. | |
| Analizada | Crítica (9.8) | 0.36% | — | IBM Operations Analytics LOG Analysis | 27/5/2026 | 17/6/2026 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier for attackers to… | |
| Aplazada | Alta (7.1) | 0.22% | — | Digital Operations Services INC WifiburadaAI | 21/5/2026 | 23/7/2026 | Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. This issue affects WifiBurada: through 21052026. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Analizada | Alta (8.8) | 0.22% | — | Veritas Infoscale Operations Manager | 20/5/2026 | 23/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge. | |
| Analizada | Media (5.4) | 0.24% | — | Veritas Infoscale Operations Manager | 20/5/2026 | 23/7/2026 | InfoScale VIOM 9.1.3 allows XSS. | |
| Analizada | Media (6.5) | 0.35% | — | Veritas Infoscale Operations Manager | 20/5/2026 | 23/7/2026 | SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges. | |
| Aplazada | Alta (7.1) | 0.18% | — | ABB Ac800mAIABB Symphony Plus SD SeriesAIABB Symphony Plus MRAIABB S+ OperationsAI+3 | 13/4/2026 | 17/6/2026 | A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed as affected in this CVE. An attacker with access to IEC 61850 networks could exploit the vulnera bility by using a specially crafted 61850 packet, forcing the communication interfaces of the PM… | |
| Analizada | Media (5.5) | 0.14% | — | Hitachi JOB Management Partner 1/it Desktop Management-managerHitachi Jp1/it Desktop Management 2-managerHitachi Jp1/it Desktop Management 2-operations DirectorHitachi Jp1/netm/dm Manager+1 | 7/4/2026 | 17/6/2026 | Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management -… | |
| Analizada | Crítica (9.8) | 0.61% | — | Hitachi JOB Management Partner 1/it Desktop Management-managerHitachi Jp1/it Desktop Management 2-managerHitachi Jp1/it Desktop Management 2-operations DirectorHitachi Jp1/netm/dm Manager+1 | 7/4/2026 | 17/6/2026 | Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management -… | |
| Analizada | Alta (8.6) | 0.10% | — | Microfocus Operations Agent | 31/3/2026 | 24/7/2026 | A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerability | |
| Analizada | Alta (8.8) | 1.1% | — | Microsoft System Center Operations Manager | 10/3/2026 | 17/6/2026 | Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.2) | 0.71% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of… | |
| Analizada | Crítica (9) | 0.42% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the… | |
| Analizada | Alta (8.1) | 18% | ⚠ Explotación activa | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the… | |
| Aplazada | Media (4.3) | 0.15% | — | IBM Operations Analytics LOG AnalysisAIIBM Smartcloud Analytics LOG AnalysisAI | 4/2/2026 | 17/6/2026 | IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are vulnerable to a cross-site request forgery (CSRF) vulnerability that could allow an attacker to trick a trusted user into performing unauthorized actions. | |
| Analizada | Alta (8.6) | 0.33% | — | Google Security Operations Soar | 9/12/2025 | 30/9/2026 | A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an "IDE role" to achieve Remote Code Execution (RCE) in the server. The flaw stemmed from weak validation of uploaded Python package code. An attacker could upload a package containing a malicious… | |
| Aplazada | Media (4.9) | 0.61% | — | Vmware Aria OperationsAI | 29/9/2025 | 17/6/2026 | VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of other users of Aria Operations. | |
| Analizada | Alta (7.8) | 8.4% | ⚠ Explotación activa | Vmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+4 | 29/9/2025 | 17/6/2026 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the… | |
| Aplazada | Crítica (9.4) | 0.35% | — | Opentext Operations Bridge ManagerAI | 7/5/2025 | 17/6/2026 | Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated users.This issue affects Operations Bridge Manager: 2023.05, 23.4, 24.2, 24.4. | |
| Aplazada | Media (6.7) | 0.18% | — | Opentext Operations Bridge ManagerAI | 7/5/2025 | 17/6/2026 | Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allow authenticated users to change their password without providing their old password. This issue affects Operations Bridge Manager: 24.2, 24.4. |