Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
223 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle Demand Signal RepositoryAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.… | |
| Pendiente de análisis | Alta (8.1) | 0.43% | — | Oracle Demand Signal RepositoryAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.… | |
| Pendiente de análisis | Alta (8.1) | 0.35% | — | Oracle Demand Signal RepositoryAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.… | |
| Pendiente de análisis | Alta (8.1) | 0.35% | — | Oracle Demand Signal RepositoryAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.… | |
| Pendiente de análisis | Alta (8.1) | 0.35% | — | Oracle Demand Signal RepositoryAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.… | |
| Aplazada | Media (5.8) | 0.30% | — | Signalk Signal K ServerAI | 15/9/2026 | 30/9/2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters from the testSignalKConnection, requestAccess, and checkAccessRequest endpoints without validating the… | |
| Aplazada | Alta (7.5) | 0.50% | — | Signalwire LibksAI | 11/9/2026 | 30/9/2026 | libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".."… | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | Redpine Signals Rs9116wAIRedpine Signals Siwx917AI | 8/9/2026 | 8/9/2026 | An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below. | |
| Pendiente de análisis | Alta (8.8) | 0.35% | — | Redpine Signals Rs9116wAISilabs Siwx917AI | 13/8/2026 | 8/9/2026 | Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below | |
| Aplazada | Media (6.5) | 0.34% | — | Humansignal Label StudioAI | 11/8/2026 | 3/9/2026 | A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by default. The import-from-URL endpoint fetches any caller-supplied URL including internal loopback addresses on the default installation. An authenticated user can use… | |
| Aplazada | Alta (7.5) | 0.46% | — | SignalrgbAI | 17/6/2026 | 22/6/2026 | In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer without first verifying that it is non-NULL. Sending an IOCTL with an empty input buffer causes a NULL pointer dereference, resulting in a kernel crash. | |
| Aplazada | Media (5.3) | 0.12% | — | Corsair SignalrgbAI | 17/6/2026 | 22/6/2026 | In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security descriptor and without FILE_DEVICE_SECURE_OPEN. This results in overly permissive default access control, allowing any authenticated local user to obtain a handle to the device and issue privileged… | |
| Pendiente de análisis | Alta (7.4) | 0.25% | — | Redpine Signals Rs9116AI | 14/5/2026 | 17/6/2026 | Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values | |
| Analizada | Alta (8.7) | 0.51% | — | Signalk Signal K Server | 9/5/2026 | 24/7/2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are protected by express-rate-limit (default: 100 attempts per 10-minute window, configurable via HTTP_RATE_LIMITS). The WebSocket login path —… | |
| Analizada | Alta (8.5) | 0.20% | — | Oracle Life Sciences Empirica Signal | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are affected are 9.2.1-9.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences Empirica… | |
| Analizada | Alta (7.5) | 0.66% | — | Signalk Signal K Server | 21/4/2026 | 17/6/2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular Expression Denial of Service (ReDoS) attack within the WebSocket subscription handling logic. By injecting unescaped regex metacharacters into the `context` parameter of a… | |
| Aplazada | Baja (3.1) | 0.28% | — | OnesignalAI | 16/4/2026 | 17/6/2026 | The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Analizada | Baja (2.1) | 0.41% | — | Signalk Signal K Server | 2/4/2026 | 21/7/2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated user to bypass prototype boundary filtering to extract internal functions and… | |
| Analizada | Media (6.1) | 0.14% | — | Signalk Signal K Server | 2/4/2026 | 24/7/2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server contains a code-level vulnerability in its OIDC login and logout handlers where the unvalidated HTTP Host header is used to construct the OAuth2 redirect_uri. Because the redirectUri configuration is… | |
| Analizada | Media (6.9) | 0.54% | — | Signalk Signal K Server | 2/4/2026 | 24/7/2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the SignalK Server exposes an unauthenticated HTTP endpoint that allows remote attackers to modify navigation data source priorities. This endpoint, accessible via PUT /signalk/v1/api/sourcePriorities, does… | |
| Analizada | Crítica (9.4) | 0.48% | — | Signalk Signal K Server | 2/4/2026 | 24/7/2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /enableSecurity. An unauthenticated attacker can gain full Administrator access to the SignalK server at any time, allowing them to… | |
| Analizada | Media (4.3) | 0.43% | — | Signalk Signal K Server | 2/2/2026 | 17/6/2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerability in SignalK Server's applicationData API allows authenticated users on Windows systems to read, write, and list arbitrary files and directories on the filesystem. The validateAppId() function… | |
| Analizada | Alta (8.8) | 4.6% | — | Signalk Signal K Server | 2/2/2026 | 17/6/2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated users can also exploit… | |
| Analizada | Alta (8.6) | 0.28% | — | Humansignal Label Studio | 12/1/2026 | 17/6/2026 | Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can… | |
| Analizada | Alta (8.8) | 0.30% | — | Signalk Signal K Server | 1/1/2026 | 1/10/2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features that when combined by themselves and with an information disclosure vulnerability enable convincing social engineering attacks against administrators. When a… |