Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 212 respecto a la semana anterior
Críticas / altas1386▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.25% | — | Pega PlatformAI | 28/8/2026 | 8/9/2026 | Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping. | |
| Pendiente de análisis | Alta (8.6) | 0.78% | — | Pega PlatformAI | 10/8/2026 | 8/9/2026 | Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls. | |
| Pendiente de análisis | Media (4.6) | 0.42% | — | Pega PlatformAI | 4/8/2026 | 8/9/2026 | Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. | |
| Analizada | Media (4.8) | 0.24% | — | Pega Platform | 15/7/2026 | 21/7/2026 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. | |
| Analizada | Media (4.6) | 0.24% | — | Pega Platform | 15/7/2026 | 21/7/2026 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. | |
| Pendiente de análisis | Alta (7.1) | 0.36% | — | Pega PlatformAI | 23/6/2026 | 30/9/2026 | Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs. | |
| Analizada | Media (4.8) | 0.19% | — | Pega Platform | 15/4/2026 | 17/6/2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role. | |
| Analizada | Media (5.1) | 0.19% | — | Pega Platform | 15/4/2026 | 17/6/2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role. | |
| Analizada | Media (4.8) | 0.26% | — | Pega Platform | 31/3/2026 | 24/7/2026 | Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none. | |
| Aplazada | Media (4.8) | 0.26% | — | Pega PlatformAI | 17/2/2026 | 17/6/2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low. | |
| Aplazada | Media (5.3) | 0.44% | — | Pega PlatformAI | 10/12/2025 | 28/9/2026 | Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. This only applies to deprecated basic-authentication… | |
| Analizada | Media (6.5) | 0.40% | — | Pega Platform | 16/10/2025 | 17/6/2026 | Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data. | |
| Analizada | Media (5.4) | 0.19% | — | Pega Platform | 10/9/2025 | 25/9/2026 | Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role. | |
| Analizada | Media (6.1) | 0.28% | — | Pega Platform | 14/4/2025 | 17/6/2026 | Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup | |
| Analizada | Media (6.1) | 0.28% | — | Pega Platform | 14/4/2025 | 17/6/2026 | Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup | |
| Analizada | Media (5.4) | 0.32% | — | Pega Platform | 13/1/2025 | 17/6/2026 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile. | |
| Analizada | Alta (7.7) | 0.39% | — | Pega Platform | 14/3/2024 | 17/6/2026 | Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation. | |
| Analizada | Media (6.1) | 0.30% | — | Pega Platform | 6/3/2024 | 17/6/2026 | Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content. | |
| Modificada | Media (4.8) | 0.34% | — | Pega Platform | 8/9/2023 | 17/6/2026 | Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user. | |
| Modificada | Crítica (9.8) | 0.62% | — | Pega Platform | 7/8/2023 | 17/6/2026 | Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials | |
| Modificada | Crítica (9.8) | 0.53% | — | Pega Platform | 22/6/2023 | 17/6/2026 | Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials. | |
| Modificada | Media (6.1) | 0.44% | — | Pega Platform | 9/6/2023 | 17/6/2026 | Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue. | |
| Modificada | Media (4.5) | 0.33% | — | Pega Platform | 22/8/2022 | 17/6/2026 | Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly. | |
| Modificada | Media (6.1) | 0.47% | — | Pega Platform | 22/8/2022 | 17/6/2026 | Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting. | |
| Modificada | Media (6.1) | 0.52% | — | Pega Platform | 22/8/2022 | 17/6/2026 | Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. |