Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

2621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.29%—Hitachi Coding Software SuiteAI1/10/20261/10/2026
Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials. This issue affects Hitachi Coding Software Suite: through 3.3.0.
AplazadaAlta (8.7)0.23%—Hitachi Coding Software SuiteAI1/10/20261/10/2026
Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations. This issue affects Hitachi Coding Software Suite: through 3.3.0.
AplazadaCrítica (9.3)0.27%—Hitachi Coding Software SuiteAI1/10/20261/10/2026
Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding Software Suite: through 3.3.0.
AplazadaAlta (8.7)0.18%—Hitachi Coding Software SuiteAI1/10/20261/10/2026
Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials and sensitive data in transit. This issue affects Hitachi Coding Software Suite: through 3.3.0.
AplazadaCrítica (9.3)0.34%—Hitachi Coding Software SuiteAI1/10/20261/10/2026
Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation. This issue affects…
AplazadaCrítica (9.3)0.38%—Hitachi Coding Software SuiteAI1/10/20261/10/2026
Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0.
Pendiente de análisisAlta (8.5)0.25%—Hitachienergy Asset SuiteAI29/9/202629/9/2026
Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.
Pendiente de análisisMedia (5.1)0.25%—Hitachienergy Asset SuiteAI29/9/202629/9/2026
Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production…
AplazadaMedia (6.8)0.22%—SPS SuiteAI28/9/202628/9/2026
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
AplazadaAlta (7.5)0.36%—Ciena Navigator Network Control SuiteAI25/9/202628/9/2026
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.
AplazadaMedia (6.5)0.25%—Lasuite DOCAI24/9/20265/10/2026
LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/documents/search/ accepts sequential seven-digit document paths to scope descendant searches without requiring the caller to possess the public document UUID. An unauthenticated caller can submit an empty…
Pendiente de análisisCrítica (9.2)0.33%—Portswigger Burp Suite DastAI24/9/202624/9/2026
In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.
AplazadaMedia (6.5)0.11%—Fabasoft Folio ClientAIFabasoft Egov-suiteAI24/9/202626/9/2026
Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default,…
Pendiente de análisisMedia (5.5)0.13%—Dell Command Integration Suite FOR System CenterAI21/9/202622/9/2026
Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
Pendiente de análisisAlta (8.8)0.42%—Oracle E-business SuiteAIOracle Contract Lifecycle Management FOR Public SectorAI15/9/202617/9/2026
Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: ECC For Award and IDV). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract…
Pendiente de análisisAlta (8.8)0.42%—Oracle Bills OF MaterialAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks…
Pendiente de análisisAlta (8)0.36%—Oracle Advanced BenefitsAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits.…
Pendiente de análisisAlta (7.2)0.46%—Oracle ContractsAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this…
Pendiente de análisisAlta (7.2)0.46%—Oracle E-business SuiteAIOracle ContractsAI15/9/202617/9/2026
Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this…
Pendiente de análisisAlta (8.8)0.42%—Oracle E-business SuiteAIOracle ContractsAI15/9/202617/9/2026
Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this…
Pendiente de análisisAlta (8.1)0.37%—Oracle Mobile Application ServerAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
Pendiente de análisisAlta (7.5)0.24%—Oracle Mobile Application ServerAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the…
Pendiente de análisisCrítica (9.8)0.48%—Oracle Mobile Application ServerAIOracle E-business SuiteAI15/9/202616/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
Pendiente de análisisAlta (8.8)0.42%—Oracle Demand Signal RepositoryAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.…
Pendiente de análisisAlta (8.8)0.42%—Oracle Document Management AND CollaborationAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document…