Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
208 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.3) | 0.14% | — | GNU LibextractorAI | 25/9/2026 | 30/9/2026 | GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Contract Lifecycle Management FOR Public SectorAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: ECC For Award and IDV). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle Contract Lifecycle Management FOR Public SectorAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award/PO). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract… | |
| Pendiente de análisis | Alta (7.2) | 0.46% | — | Oracle ContractsAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this… | |
| Pendiente de análisis | Alta (7.2) | 0.46% | — | Oracle E-business SuiteAIOracle ContractsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle ContractsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this… | |
| Pendiente de análisis | Media (6.1) | 0.24% | — | Oracle Contract Lifecycle Management FOR Public SectorAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Wage Determination Online). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Oracle E-business SuiteAIOracle Contract Lifecycle Management FOR Public SectorAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award/PO). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract… | |
| Pendiente de análisis | Alta (8.7) | 0.74% | — | GNU LibextractorAI | 14/9/2026 | 24/9/2026 | GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB on the stack, causing stack overflow and… | |
| Aplazada | Media (6.1) | 0.18% | — | TractAI | 14/9/2026 | 30/9/2026 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor for attacker-controlled tensor dimensions, the allocation size, and the reported tensor length. Loading a crafted… | |
| Aplazada | Media (6.1) | 0.19% | — | TractAI | 14/9/2026 | 30/9/2026 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model through onnx/src/tensor.rs get_external_resources and joins the value to the model directory without… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Service Contracts | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Contracts. Successful… | |
| Aplazada | Baja (2.1) | 0.59% | — | Sonos TractAI | 18/8/2026 | 20/8/2026 | A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_align of the file data/src/tensor.rs of the component ONNX Initializer Loader. Such manipulation leads to incorrect calculation of buffer size. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Alta (8.1) | 0.28% | — | Max-mapper Extract-zipAI | 17/8/2026 | 9/9/2026 | extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and… | |
| Aplazada | Media (6.6) | 0.52% | — | Openzeppelin Confidential ContractsAIZama FhevmAI | 13/8/2026 | 18/9/2026 | OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0.3.1, the ERC7984 contract tracked confidential total supply with an euint64 value, and an overflowing internal _mint operation could fail silently. The wrap and onTransferReceived functions in… | |
| Aplazada | Alta (8.8) | 0.64% | — | Openzeppelin Contracts WizardAIHardhatAI | 6/8/2026 | 14/9/2026 | OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri` (ERC1155) directly into TypeScript string… | |
| Aplazada | Alta (7.5) | 0.39% | — | Formidable Forms Signature Online Contract AutomationAI | 6/8/2026 | 12/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | |
| Analizada | Media (4.3) | 0.26% | — | Oracle Project Contracts | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful… | |
| Analizada | Alta (8.8) | 0.16% | — | Oracle Peoplesoft Enterprise SCM Supplier Contract Management | 21/7/2026 | 4/8/2026 | Vulnerability in the PeopleSoft Enterprise SCM Supplier Contract Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Supplier… | |
| Analizada | Media (5.7) | 0.29% | — | Oracle Service Contracts | 21/7/2026 | 11/8/2026 | Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Service Contracts. Successful… | |
| Analizada | Baja (3.1) | 0.25% | — | Oracle Project Contracts | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Project Contracts | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle JD Edwards Enterpriseone Procurement AND Subcontract Management | 21/7/2026 | 5/8/2026 | Vulnerability in the JD Edwards EnterpriseOne Procurement and Subcontract Management product of Oracle JD Edwards (component: Procurement). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne… | |
| Analizada | Media (6.5) | 1.2% | — | Ivanti Xtraction | 14/7/2026 | 6/8/2026 | Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root. | |
| Analizada | Media (6.1) | 0.71% | — | Ivanti Xtraction | 14/7/2026 | 6/8/2026 | An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs. |