Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3038▲ 464 respecto a la semana anterior
Críticas / altas1416▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)387▲ 170 respecto a la semana anterior
583 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.44% | — | Internlm LmdeployAI | 18/9/2026 | 24/9/2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitrary Python code by publishing a malicious HuggingFace model with a crafted… | |
| Pendiente de análisis | Crítica (9.8) | 0.69% | — | ZeromqAIPyzmqAIInternlm LmdeployAI | 18/9/2026 | 23/9/2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL socket. PyZMQ implements `recv_pyobj()`… | |
| Pendiente de análisis | Media (6.5) | 0.38% | — | HCL Devops DeployAIHCL LaunchAI | 17/9/2026 | 18/9/2026 | HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside… | |
| Aplazada | Alta (8.7) | 0.66% | — | Internlm LmdeployAIDistserveAI | 17/9/2026 | 22/9/2026 | InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys. Unauthenticated attackers can send completion requests to the proxy endpoint that accumulate unreleased scheduler… | |
| Aplazada | Alta (8.7) | 0.70% | — | Internlm LmdeployAI | 17/9/2026 | 22/9/2026 | InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remote_block_ids list to trigger an AssertionError that crashes the engine… | |
| Aplazada | Crítica (9.8) | 0.80% | — | Internlm LmdeployAI | 16/9/2026 | 24/9/2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability… | |
| Aplazada | Alta (7.1) | 0.36% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this… | |
| Aplazada | Alta (7.1) | 0.14% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM… | |
| Aplazada | Alta (7.4) | 0.32% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this… | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM… | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM… | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM… | |
| Aplazada | Alta (8.8) | 0.52% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Deployment. Successful attacks of this… | |
| Aplazada | Alta (8.8) | 0.52% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Deployment. Successful attacks of this vulnerability… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is… | |
| Aplazada | Alta (7.2) | 0.46% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this… | |
| Aplazada | Alta (8.1) | 0.37% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this… | |
| Aplazada | Alta (7.3) | 0.14% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Siebel CRM DeploymentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this… | |
| Pendiente de análisis | Media (6.5) | 0.38% | — | IBM Urbancode DeployAIIBM Devops DeployAI | 4/9/2026 | 10/9/2026 | IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property… | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Xebialabs XL DeployAIJenkinsAI | 2/9/2026 | 3/9/2026 | Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Aplazada | Crítica (9.3) | 1.3% | — | Internlm LmdeployAI | 19/8/2026 | 24/9/2026 | LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the isinstance check against… | |
| Analizada | Media (4.3) | 0.30% | — | IBM Devops DeployIBM Urbancode Deploy | 30/7/2026 | 10/8/2026 | IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access… |