Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.4) | — | — | Process-one EjabberdAI | 2/10/2026 | 2/10/2026 | User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism. | |
| Aplazada | Media (5.1) | 0.26% | — | Process ComposeAI | 18/9/2026 | 24/9/2026 | Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating the Host header, validating the Origin header, or authenticating the caller. When… | |
| Aplazada | Alta (7.1) | 0.27% | — | Oracle Banking Corporate Lending Process ManagementAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Aplazada | Media (6.5) | 0.34% | — | Oracle E-business SuiteAIOracle Process Manufacturing IntelligenceAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Process… | |
| Pendiente de análisis | Alta (8.1) | 0.27% | — | Oracle Work IN ProcessAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Workbenches). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle… | |
| Pendiente de análisis | Media (5.7) | 0.16% | — | Samsung Automotive Processor Exynos Auto 8890AISamsung Automotive Processor Exynos Auto V7AISamsung Automotive Processor Exynos Auto V9AISamsung Automotive Processor Exynos Auto V920AI | 13/9/2026 | 28/9/2026 | An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel. | |
| Pendiente de análisis | Baja (2.2) | 0.34% | — | SAP Process IntegrationAI | 8/9/2026 | 8/9/2026 | SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with… | |
| Aplazada | Alta (8.7) | 0.48% | — | OWL DocumentprocessingtoolkitAI | 4/9/2026 | 24/9/2026 | OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses… | |
| Aplazada | Crítica (9.1) | 0.24% | — | Totalpaymentprocessing Total Processing Card PaymentsAI | 29/8/2026 | 31/8/2026 | The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Process Manufacturing Systems | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Process Manufacturing Systems | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle MES FOR Process Manufacturing | 18/8/2026 | 3/9/2026 | Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle MES for Process… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Work IN Process | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks… | |
| Analizada | Alta (7.1) | 0.32% | — | Oracle Work IN Process | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks… | |
| Analizada | Alta (7) | 0.13% | — | Oracle Work IN Process | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to… | |
| Analizada | Alta (8.2) | 0.32% | — | Oracle MES FOR Process Manufacturing | 18/8/2026 | 3/9/2026 | Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process… | |
| Aplazada | Crítica (9.1) | 0.56% | — | Form Processor Field HtmlareaAIPerl Html TidyAIPerl Locale MaketextAI | 13/8/2026 | 26/8/2026 | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the submitted markup and passes each resulting… | |
| Pendiente de análisis | Media (4) | 0.11% | — | Intel ProcessorsAI | 11/8/2026 | 12/8/2026 | Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This… | |
| Analizada | Media (6.9) | 0.10% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 31/8/2026 | Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local… | |
| Analizada | Media (6.9) | 0.13% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 31/8/2026 | Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Intel ProcessorsAI | 11/8/2026 | 12/8/2026 | Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially… | |
| Analizada | Media (6.9) | 0.10% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 31/8/2026 | Improper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access… | |
| En análisis | Media (4.5) | 0.10% | — | Intel Xeon ProcessorAI | 11/8/2026 | 12/8/2026 | Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when… | |
| En análisis | Media (6.8) | 0.08% | — | Intel Xeon Scalable ProcessorsAI | 11/8/2026 | 12/8/2026 | Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially… | |
| Analizada | Media (5.8) | 0.07% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 28/9/2026 | Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially… |