Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 319 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
414 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.9) | 0.35% | — | Pdfme CommonAI | 31/8/2026 | 10/9/2026 | @pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template field can force servers or clients to make requests to internal endpoints,… | |
| Analizada | Alta (7.6) | 0.43% | — | Broadcom Spring Cloud Commons | 27/8/2026 | 1/9/2026 | There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commons 5.0.0 - 5.0.2 Spring Cloud Commons 4.3.0 - 4.3.3 Spring Cloud Commons 4.0.0 - 4.2.6 Spring Cloud Commons 3.1.10 and earlier | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 18/8/2026 | 4/9/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects.… | |
| En análisis | Alta (7.2) | 0.46% | — | Oracle Peoplesoft Enterprise FIN Common Objects BrazilAI | 18/8/2026 | 21/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.1. Easily exploitable vulnerability allows high privileged attacker with network access via T3, IIOP to compromise PeopleSoft Enterprise FIN Common… | |
| Analizada | Alta (8.2) | 0.35% | — | Oracle HCM Common Architecture | 18/8/2026 | 3/9/2026 | Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture.… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Peoplesoft Enterprise CC Common Application Objects | 18/8/2026 | 4/9/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise PeopleSoft… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Thephpleague CommonmarkAI | 6/8/2026 | 10/9/2026 | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character… | |
| Pendiente de análisis | Media (6.1) | 0.36% | — | Thephpleague CommonmarkAI | 6/8/2026 | 10/9/2026 | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers… | |
| Aplazada | Media (5.1) | 0.31% | — | Milkdown Preset CommonmarkAITennisconnect ComponentsAI | 24/7/2026 | 27/7/2026 | Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rendered link. The… | |
| Analizada | Media (6.3) | 0.27% | — | Oracle Common Applications Calendar | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects… | |
| Analizada | Alta (8.2) | 0.32% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware… | |
| Analizada | Crítica (9.9) | 0.37% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common… | |
| Analizada | Crítica (9.9) | 0.38% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common… | |
| Analizada | Crítica (9) | 0.39% | — | Oracle Peoplesoft Enterprise CRM Common Objects | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CRM Common… | |
| Analizada | Alta (8.7) | 0.33% | — | Oracle Peoplesoft Enterprise CC Common Application Objects | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects… | |
| Analizada | Media (5.3) | 0.41% | — | Oracle Peoplesoft Enterprise FIN Common Objects | 21/7/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Cash Management). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common… |