Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
4643 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 1.1% | — | Sage Employee Self ServiceAI | 1/9/2026 | 9/9/2026 | Existe una vulnerabilidad de recorrido de directorios (path traversal) en la funcionalidad de logotipo personalizado de Sage Employee Self Service debido a una validación incorrecta de los parámetros de ruta de archivo. Aprovechando secuencias de recorrido de directorios y sus variantes codificadas, un atacante puede… | |
| Pendiente de análisis | Crítica (10) | 0.42% | — | Servicenow AI PlatformAI | 27/8/2026 | 1/9/2026 | ServiceNow ha corregido una vulnerabilidad de inyección SQL identificada en la ServiceNow AI platform. Esta vulnerabilidad podría permitir a un usuario no autenticado, en determinadas circunstancias, ejecutar sentencias SQL arbitrarias contra la base de datos subyacente de la instancia y obtener acceso a los datos de… | |
| Pendiente de análisis | Crítica (10) | 0.62% | — | Servicenow AI PlatformAI | 27/8/2026 | 1/9/2026 | ServiceNow ha corregido un problema de seguridad de escape del sandbox identificado en la ServiceNow AI Platform. Este problema de seguridad podría permitir a un usuario no autenticado ejecutar código arbitrario dentro de la ServiceNow AI Platform, lo que podría dar lugar a un acceso a la ServiceNow AI Platform mayor… | |
| Pendiente de análisis | Crítica (10) | 5.0% | — | Servicenow AI PlatformAI | 27/8/2026 | 3/9/2026 | ServiceNow ha corregido una vulnerabilidad de control de acceso inadecuado identificada en la ServiceNow AI platform. Esta vulnerabilidad podría permitir a un usuario no autenticado, en determinadas circunstancias, crear o modificar datos de la instancia más allá de lo previsto, lo que daría lugar a una escalada de… | |
| Pendiente de análisis | Crítica (10) | 7.2% | — | Servicenow AI PlatformAI | 27/8/2026 | 1/9/2026 | ServiceNow ha corregido una vulnerabilidad de inyección de código identificada en la ServiceNow AI platform. Esta vulnerabilidad podría permitir a un usuario no autenticado, en determinadas circunstancias, ejecutar código arbitrario en la plataforma ServiceNow y obtener acceso a los datos de la instancia, o… | |
| Pendiente de análisis | Crítica (9.4) | 0.45% | — | Google Cloud Bigquery Data Transfer ServiceAICdata Jdbc DriverAI | 26/8/2026 | 31/8/2026 | Una vulnerabilidad de validación de entrada incorrecta en la integración del controlador JDBC de CData en Google Cloud BigQuery Data Transfer Service en versiones anteriores a 2026-05-01 en Google Cloud Platform permite a un atacante autenticado lograr la ejecución remota de código en el contenedor del conector y… | |
| Aplazada | Crítica (9.8) | 0.88% | — | Beijing Tongtech TongwebAIVmware HttpinvokerserviceexporterAI | 25/8/2026 | 31/8/2026 | Un problema en Beijing Tongtech Co., Ltd tongweb v.7.0.24 en el componente Spring HttpInovkerServiceExporter permite a un atacante remoto ejecutar código arbitrario mediante una solicitud manipulada al endpoint console/heimdall | |
| Aplazada | Alta (7.5) | 0.63% | — | Fuyaweb Internet AND Informatics Services Architectpanel WEB Admin PanelAI | 21/8/2026 | 26/8/2026 | Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: through 28072026. | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | Canonical AccountsserviceAI | 20/8/2026 | 28/8/2026 | The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | Canonical AccountsserviceAI | 20/8/2026 | 28/8/2026 | An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to… | |
| Analizada | Alta (8.8) | 0.42% | — | Oracle Hospitality Opera 5 Property Services | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.28.0-5.6.28.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (8.1) | 0.39% | — | Oracle WEB Services Manager | 18/8/2026 | 22/8/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Web Services… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Financial Services Enterprise Case Management | 18/8/2026 | 11/9/2026 | Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.2 and 8.1.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Crítica (9.3) | 0.36% | — | Oracle Siebel Apps - Self ServiceAI | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Self Service. Successful attacks… | |
| Analizada | Alta (7.3) | 0.16% | — | Oracle Service Delivery Platform Number Portability | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SDP Number Portability executes… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Service Delivery Platform Number Portability | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SDP Number Portability.… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Service Fulfillment Manager | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Service Contracts | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Contracts. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Teleservice | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Request Form). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Teleservice. Successful attacks of… | |
| Modificada | Crítica (9.6) | 0.36% | — | Oracle WEB Services Manager | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Services… | |
| Analizada | Media (6.5) | 0.27% | — | Oracle Service Delivery Platform | 18/8/2026 | 21/8/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful… | |
| Analizada | Media (6.8) | 0.40% | — | Oracle Service Delivery Platform | 18/8/2026 | 21/8/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Service Delivery Platform.… | |
| Analizada | Crítica (9.6) | 0.36% | — | Oracle Service Delivery Platform | 18/8/2026 | 21/8/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Service Delivery… | |
| Analizada | Alta (8.7) | 0.36% | — | Oracle Service Delivery Platform | 18/8/2026 | 21/8/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Service Delivery Platform.… | |
| Modificada | Crítica (9.1) | 0.43% | — | Oracle WEB Services Manager | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services… |