Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.34% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.… | |
| Analizada | Media (4.4) | 0.14% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management… | |
| Analizada | Media (6.4) | 0.26% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.… | |
| Analizada | Media (6.5) | 0.15% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to… | |
| Analizada | Baja (2.8) | 0.14% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to… | |
| Analizada | Crítica (9.4) | 0.41% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Peoplesoft Enterprise SCM Manufacturing | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Manufacturing. Successful… | |
| Analizada | Baja (3.3) | 0.21% | — | Oracle Peoplesoft Enterprise FIN Engineering Argentina | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Engineering… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Process Manufacturing Product Development | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Process Manufacturing Systems | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Process Manufacturing Systems | 21/7/2026 | 12/8/2026 | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing… | |
| Analizada | Media (5.4) | 0.12% | — | Oracle Flow Manufacturing | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful… | |
| Analizada | Baja (3.1) | 0.25% | — | Oracle Project Manufacturing | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Manufacturing. Successful… | |
| Analizada | Baja (3.6) | 0.11% | — | Oracle Project Manufacturing | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to… | |
| Analizada | Media (4.7) | 0.14% | — | Oracle Project Manufacturing | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to… | |
| Analizada | Media (5.7) | 0.14% | — | Oracle Project Manufacturing | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to… | |
| En análisis | Media (5.7) | 0.14% | — | Oracle Project Manufacturing | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to… | |
| Aplazada | Baja (3.8) | 0.14% | — | Data Ringbuffer SharedAI | 21/7/2026 | 23/7/2026 | Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW… | |
| Aplazada | Media (5.5) | 0.15% | — | Data Roaringbitmap SharedAI | 21/7/2026 | 24/7/2026 | Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in roaring.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable).… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Perl Data Ringbuffer SharedAI | 21/7/2026 | 22/7/2026 | Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and total_size consistency of the header but never caps elem_size against the destination size. ring_read_seq… | |
| Aplazada | Media (6.3) | 0.29% | — | Data Roaringbitmap SharedAI | 21/7/2026 | 23/7/2026 | Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked. The attach-time validator rb_validate_header checks the header scalars and region layout against the file size, but does not validate the bucket contents it… | |
| Aplazada | Media (5.4) | 0.23% | — | Bifra Engineering Consulting LTD Q-smart Next PollAI | 20/7/2026 | 20/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects Q-smart NexT Poll: before 1.8.7. | |
| Aplazada | Crítica (9.1) | 0.32% | — | LettreAILettre Boring-tlsAI | 20/7/2026 | 23/7/2026 | lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently disables TLS hostname verification for callers using the default (strict) configuration. An on-path attacker presenting any chain-valid certificate for… | |
| Analizada | Alta (7.5) | 0.52% | — | IBM Engineering AI HUB | 17/7/2026 | 24/7/2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs. | |
| Analizada | Media (4.3) | 0.36% | — | IBM Engineering AI HUB | 17/7/2026 | 24/7/2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs. |