Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

807 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.26%—Process ComposeAI18/9/202624/9/2026
Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating the Host header, validating the Origin header, or authenticating the caller. When…
AplazadaAlta (7.1)0.27%—Oracle Banking Corporate Lending Process ManagementAI15/9/202617/9/2026
Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…
AplazadaMedia (6.5)0.34%—Oracle E-business SuiteAIOracle Process Manufacturing IntelligenceAI15/9/202617/9/2026
Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Process…
Pendiente de análisisAlta (8.1)0.27%—Oracle Work IN ProcessAIOracle E-business SuiteAI15/9/202618/9/2026
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Workbenches). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle…
Pendiente de análisisMedia (5.7)0.16%—Samsung Automotive Processor Exynos Auto 8890AISamsung Automotive Processor Exynos Auto V7AISamsung Automotive Processor Exynos Auto V9AISamsung Automotive Processor Exynos Auto V920AI13/9/202628/9/2026
An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.
Pendiente de análisisBaja (2.2)0.34%—SAP Process IntegrationAI8/9/20268/9/2026
SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with…
AplazadaAlta (8.7)0.48%—OWL DocumentprocessingtoolkitAI4/9/202624/9/2026
OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses…
AplazadaCrítica (9.1)0.24%—Totalpaymentprocessing Total Processing Card PaymentsAI29/8/202631/8/2026
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host…
AnalizadaAlta (8.1)0.36%—Oracle Process Manufacturing Systems18/8/202628/8/2026
Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing…
AnalizadaAlta (7.5)0.33%—Oracle Process Manufacturing Systems18/8/202628/8/2026
Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process…
AnalizadaAlta (7.7)0.35%—Oracle MES FOR Process Manufacturing18/8/20263/9/2026
Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle MES for Process…
AnalizadaAlta (8.8)0.43%—Oracle Work IN Process18/8/202631/8/2026
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks…
AnalizadaAlta (7.1)0.32%—Oracle Work IN Process18/8/202631/8/2026
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks…
AnalizadaAlta (7)0.13%—Oracle Work IN Process18/8/202631/8/2026
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to…
AnalizadaAlta (8.2)0.32%—Oracle MES FOR Process Manufacturing18/8/20263/9/2026
Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process…
AplazadaCrítica (9.1)0.56%—Form Processor Field HtmlareaAIPerl Html TidyAIPerl Locale MaketextAI13/8/202626/8/2026
Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the submitted markup and passes each resulting…
Pendiente de análisisMedia (4)0.11%—Intel ProcessorsAI11/8/202612/8/2026
Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This…
AnalizadaMedia (6.9)0.10%—Intel Neural Processing Unit Driver11/8/202631/8/2026
Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local…
AnalizadaMedia (6.9)0.13%—Intel Neural Processing Unit Driver11/8/202631/8/2026
Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when…
Pendiente de análisisMedia (6.8)0.10%—Intel ProcessorsAI11/8/202612/8/2026
Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially…
AnalizadaMedia (6.9)0.10%—Intel Neural Processing Unit Driver11/8/202631/8/2026
Improper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access…
En análisisMedia (4.5)0.10%—Intel Xeon ProcessorAI11/8/202612/8/2026
Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when…
En análisisMedia (6.8)0.08%—Intel Xeon Scalable ProcessorsAI11/8/202612/8/2026
Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially…
AnalizadaMedia (5.8)0.07%—Intel Neural Processing Unit Driver11/8/202628/9/2026
Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially…
AnalizadaMedia (6.9)0.13%—Intel Neural Processing Unit Driver11/8/202628/9/2026
Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack…