Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2286 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.3)0.26%—Oracle E-business Suite21/7/20267/8/2026
Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Partner Dashboard). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Partner Management. Successful…
AnalizadaMedia (6.3)0.26%—Oracle E-business Suite21/7/20266/8/2026
Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product of Oracle E-Business Suite (component: Web Service Provider). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business…
AnalizadaMedia (5.4)0.29%—Oracle E-business Suite21/7/20266/8/2026
Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SDP Number Portability. Successful…
AnalizadaCrítica (9.9)0.43%—Oracle Business Process Management Suite21/7/20267/8/2026
Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle…
AnalizadaAlta (7.2)0.49%—Oracle E-business Suite21/7/20266/8/2026
Vulnerability in the Oracle Project Costing product of Oracle E-Business Suite (component: Enterprise Command Center). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Project Costing. Successful…
AnalizadaMedia (5.4)0.23%—Oracle E-business Suite21/7/20266/8/2026
Vulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Performance Management. Successful…
AnalizadaAlta (8.5)0.33%—Oracle E-business Suite21/7/202627/7/2026
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration.…
AnalizadaAlta (8.1)0.36%—Oracle E-business Suite21/7/20266/8/2026
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document Management…
AplazadaMedia (5.5)0.43%—Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display SystemAI20/7/202620/7/2026
A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. Impacted is an unknown function of the file /admin/system/structure/updateStructure/deflate/Insecure/Staffshinel Ds.jsp?Shine ID=aaa. The manipulation of the argument Structure_ID results in…
AplazadaMedia (5.6)0.14%—Asus System Control Interface V3AIAsus System Control InterfaceAIAsus Business ManagerAI15/7/202617/9/2026
Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to the ' Security Update for ASUS System…
AplazadaAlta (8.4)0.17%—Asus System Control Interface V3AIAsus System Control InterfaceAIAsus Business ManagerAI15/7/202617/9/2026
Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the '…
AplazadaAlta (8.2)0.16%💥 PoCAsus System Control InterfaceAIAsus Business ManagerAI15/7/202617/9/2026
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a…
AnalizadaAlta (7.8)0.30%—Microsoft Surface GO 2 1901 FirmwareMicrosoft Surface GO 2 1926 FirmwareMicrosoft Surface GO 2 1927 FirmwareMicrosoft Surface GO 3 1901 Firmware+2314/7/202624/7/2026
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
AplazadaCrítica (9.3)0.40%—Quantumcloud Simple Business Directory PROAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4.
AplazadaAlta (8)0.51%—WP Business Intelligence LiteAI10/7/202610/7/2026
The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaMedia (6.4)0.35%—CM Business DirectoryAI3/7/20266/7/2026
The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaAlta (8.5)0.15%—Asus Business ManagerAI3/7/202617/9/2026
External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' section on the ASUS Security Advisory for more information.
AplazadaCrítica (9.1)0.66%—Five Star Business ProfileAISchemaAI2/7/20262/7/2026
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
AplazadaAlta (7.1)0.25%—Automotive CAR Dealership BusinessAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions.
AplazadaAlta (8.1)0.47%—Pearl Corporate BusinessAI2/7/20262/7/2026
Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.
AplazadaCrítica (9.1)0.76%—Wp-businessdirectory WP BusinessdirectoryAI1/7/20261/7/2026
The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The task=upload.remove endpoint is accessible without…
AnalizadaCrítica (9.1)0.41%—IBM Business Automation Manager30/6/20262/7/2026
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
AplazadaMedia (6.5)0.33%—Business DirectoryAI29/6/202629/6/2026
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
AplazadaMedia (6.5)0.22%—Business DirectoryAI29/6/202629/6/2026
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
AplazadaMedia (6.1)0.25%—Business DirectoryAI29/6/202629/6/2026
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.