Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.25%—Pega PlatformAI28/8/20268/9/2026
Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
Pendiente de análisisAlta (8.6)0.78%—Pega PlatformAI10/8/20268/9/2026
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.
Pendiente de análisisMedia (4.6)0.42%—Pega PlatformAI4/8/20268/9/2026
Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
AnalizadaMedia (4.8)0.24%—Pega Platform15/7/202621/7/2026
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
AnalizadaMedia (4.6)0.24%—Pega Platform15/7/202621/7/2026
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
Pendiente de análisisAlta (7.1)0.36%—Pega PlatformAI23/6/202630/9/2026
Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.
AnalizadaMedia (4.8)0.19%—Pega Platform15/4/202617/6/2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
AnalizadaMedia (5.1)0.19%—Pega Platform15/4/202617/6/2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.
AnalizadaMedia (4.8)0.26%—Pega Platform31/3/202624/7/2026
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.
AplazadaMedia (4.8)0.26%—Pega PlatformAI17/2/202617/6/2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low.
AplazadaMedia (5.3)0.44%—Pega PlatformAI10/12/202528/9/2026
Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. This only applies to deprecated basic-authentication…
AnalizadaMedia (6.5)0.40%—Pega Platform16/10/202517/6/2026
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.
AnalizadaMedia (5.4)0.19%—Pega Platform10/9/202525/9/2026
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role.
AnalizadaMedia (6.1)0.28%—Pega Platform14/4/202517/6/2026
Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
AnalizadaMedia (6.1)0.28%—Pega Platform14/4/202517/6/2026
Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
AnalizadaMedia (5.4)0.32%—Pega Platform13/1/202517/6/2026
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
AnalizadaAlta (7.7)0.39%—Pega Platform14/3/202417/6/2026
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
AnalizadaMedia (6.1)0.30%—Pega Platform6/3/202417/6/2026
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
ModificadaMedia (4.8)0.34%—Pega Platform8/9/202317/6/2026
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.
ModificadaCrítica (9.8)0.62%—Pega Platform7/8/202317/6/2026
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
ModificadaCrítica (9.8)0.53%—Pega Platform22/6/202317/6/2026
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
ModificadaMedia (6.1)0.44%—Pega Platform9/6/202317/6/2026
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
ModificadaMedia (4.5)0.33%—Pega Platform22/8/202217/6/2026
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.
ModificadaMedia (6.1)0.47%—Pega Platform22/8/202217/6/2026
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
ModificadaMedia (6.1)0.52%—Pega Platform22/8/202217/6/2026
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.