Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
8439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 0.43% | — | IBM Enterprise Build OF QuarkusAI | 24/9/2026 | 24/9/2026 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| En análisis | Crítica (9.3) | 0.89% | — | Github Enterprise ServerAI | 22/9/2026 | 24/9/2026 | A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same… | |
| En análisis | Alta (7.4) | 0.45% | — | Github Enterprise ServerAI | 22/9/2026 | 24/9/2026 | A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrote quote characters in already-sanitized HTML without re-sanitizing the result.… | |
| En análisis | Media (6) | 0.45% | — | Github Enterprise ServerAI | 22/9/2026 | 24/9/2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tokens for raw pull request diffs and patches were scoped to the repository name and… | |
| Aplazada | Alta (8.8) | 1.8% | — | Tuleap Enterprise EditionAI | 21/9/2026 | 21/9/2026 | An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server. | |
| Pendiente de análisis | Alta (8.8) | 0.66% | — | Grafana OSSAIGrafana EnterpriseAI | 17/9/2026 | 19/9/2026 | Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped… | |
| Pendiente de análisis | Crítica (10) | 0.56% | — | Altium Enterprise ServerAI | 16/9/2026 | 18/9/2026 | A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services that are reachable only from the server… | |
| Pendiente de análisis | Alta (7.7) | 0.67% | — | Kong API Gateway EnterpriseAI | 16/9/2026 | 18/9/2026 | A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing algorithm is compatible with the type of key used for verification. As a result, an… | |
| Pendiente de análisis | Alta (7) | 0.28% | — | Oracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAIOracle GraalvmAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM Enterprise Edition: 21.3.19.1; Oracle… | |
| Pendiente de análisis | Alta (7.7) | 0.30% | — | Oracle Peoplesoft Enterprise PeopletoolsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | Oracle Peoplesoft Enterprise FIN Engineering BrazilAI | 15/9/2026 | 17/9/2026 | Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Engineering Brazil… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle Enterprise Manager FOR Fusion MiddlewareAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business… | |
| Aplazada | Alta (7.2) | 0.46% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (7.5) | 0.11% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence… | |
| Aplazada | Alta (7.2) | 0.46% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Installation). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle… | |
| Aplazada | Alta (7) | 0.12% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Service Administration UI). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business… | |
| Aplazada | Alta (8.1) | 0.37% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business… | |
| Aplazada | Alta (7.5) | 0.32% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (7.5) | 0.32% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via SOAP to… | |
| Aplazada | Alta (7.8) | 0.16% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle… | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: FNDN). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise… |