Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

4643 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)1.1%—Sage Employee Self ServiceAI1/9/20269/9/2026
Existe una vulnerabilidad de recorrido de directorios (path traversal) en la funcionalidad de logotipo personalizado de Sage Employee Self Service debido a una validación incorrecta de los parámetros de ruta de archivo. Aprovechando secuencias de recorrido de directorios y sus variantes codificadas, un atacante puede…
Pendiente de análisisCrítica (10)0.42%—Servicenow AI PlatformAI27/8/20261/9/2026
ServiceNow ha corregido una vulnerabilidad de inyección SQL identificada en la ServiceNow AI platform. Esta vulnerabilidad podría permitir a un usuario no autenticado, en determinadas circunstancias, ejecutar sentencias SQL arbitrarias contra la base de datos subyacente de la instancia y obtener acceso a los datos de…
Pendiente de análisisCrítica (10)0.62%—Servicenow AI PlatformAI27/8/20261/9/2026
ServiceNow ha corregido un problema de seguridad de escape del sandbox identificado en la ServiceNow AI Platform. Este problema de seguridad podría permitir a un usuario no autenticado ejecutar código arbitrario dentro de la ServiceNow AI Platform, lo que podría dar lugar a un acceso a la ServiceNow AI Platform mayor…
Pendiente de análisisCrítica (10)5.0%—Servicenow AI PlatformAI27/8/20263/9/2026
ServiceNow ha corregido una vulnerabilidad de control de acceso inadecuado identificada en la ServiceNow AI platform. Esta vulnerabilidad podría permitir a un usuario no autenticado, en determinadas circunstancias, crear o modificar datos de la instancia más allá de lo previsto, lo que daría lugar a una escalada de…
Pendiente de análisisCrítica (10)7.2%—Servicenow AI PlatformAI27/8/20261/9/2026
ServiceNow ha corregido una vulnerabilidad de inyección de código identificada en la ServiceNow AI platform. Esta vulnerabilidad podría permitir a un usuario no autenticado, en determinadas circunstancias, ejecutar código arbitrario en la plataforma ServiceNow y obtener acceso a los datos de la instancia, o…
Pendiente de análisisCrítica (9.4)0.45%—Google Cloud Bigquery Data Transfer ServiceAICdata Jdbc DriverAI26/8/202631/8/2026
Una vulnerabilidad de validación de entrada incorrecta en la integración del controlador JDBC de CData en Google Cloud BigQuery Data Transfer Service en versiones anteriores a 2026-05-01 en Google Cloud Platform permite a un atacante autenticado lograr la ejecución remota de código en el contenedor del conector y…
AplazadaCrítica (9.8)0.88%—Beijing Tongtech TongwebAIVmware HttpinvokerserviceexporterAI25/8/202631/8/2026
Un problema en Beijing Tongtech Co., Ltd tongweb v.7.0.24 en el componente Spring HttpInovkerServiceExporter permite a un atacante remoto ejecutar código arbitrario mediante una solicitud manipulada al endpoint console/heimdall
AplazadaAlta (7.5)0.63%—Fuyaweb Internet AND Informatics Services Architectpanel WEB Admin PanelAI21/8/202626/8/2026
Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: through 28072026.
Pendiente de análisisAlta (7.8)0.19%—Canonical AccountsserviceAI20/8/202628/8/2026
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject…
Pendiente de análisisAlta (7.8)0.14%—Canonical AccountsserviceAI20/8/202628/8/2026
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to…
AnalizadaAlta (8.8)0.42%—Oracle Hospitality Opera 5 Property Services18/8/20264/9/2026
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.28.0-5.6.28.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
ModificadaAlta (8.1)0.39%—Oracle WEB Services Manager18/8/202622/8/2026
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Web Services…
AnalizadaAlta (8.8)0.43%—Oracle Financial Services Enterprise Case Management18/8/202611/9/2026
Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.2 and 8.1.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
Pendiente de análisisCrítica (9.3)0.36%—Oracle Siebel Apps - Self ServiceAI18/8/202626/8/2026
Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Self Service. Successful attacks…
AnalizadaAlta (7.3)0.16%—Oracle Service Delivery Platform Number Portability18/8/202628/8/2026
Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SDP Number Portability executes…
AnalizadaAlta (7.5)0.41%—Oracle Service Delivery Platform Number Portability18/8/202628/8/2026
Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SDP Number Portability.…
AnalizadaAlta (7.6)0.27%—Oracle Service Fulfillment Manager18/8/202628/8/2026
Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment…
AnalizadaAlta (7.4)0.34%—Oracle Service Contracts18/8/202628/8/2026
Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Contracts. Successful…
AnalizadaAlta (8.8)0.43%—Oracle Teleservice18/8/202631/8/2026
Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Request Form). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Teleservice. Successful attacks of…
ModificadaCrítica (9.6)0.36%—Oracle WEB Services Manager18/8/202624/8/2026
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Services…
AnalizadaMedia (6.5)0.27%—Oracle Service Delivery Platform18/8/202621/8/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful…
AnalizadaMedia (6.8)0.40%—Oracle Service Delivery Platform18/8/202621/8/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Service Delivery Platform.…
AnalizadaCrítica (9.6)0.36%—Oracle Service Delivery Platform18/8/202621/8/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Service Delivery…
AnalizadaAlta (8.7)0.36%—Oracle Service Delivery Platform18/8/202621/8/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Service Delivery Platform.…
ModificadaCrítica (9.1)0.43%—Oracle WEB Services Manager18/8/202620/8/2026
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services…