Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.43% | — | Oracle E-business Suite | 28/5/2026 | 21/7/2026 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Payroll. Successful attacks of this… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle E-business Suite | 28/5/2026 | 21/7/2026 | Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle E-business Suite | 28/5/2026 | 21/7/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Payments. Successful attacks of this… | |
| Analizada | Crítica (9.8) | 0.81% | ⚠ Explotación activa💥 PoC | Oracle E-business Suite | 28/5/2026 | 21/7/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this… | |
| Pendiente de análisis | Alta (8.8) | 0.44% | — | Thermo Fisher Scientific Torrent Suite DXAI | 18/5/2026 | 17/6/2026 | Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited access privileges to gain unauthorized administrator-level privileges through exploitation of specific system interfaces. | |
| Aplazada | Crítica (9.3) | 0.73% | — | Guardianwall MailsuiteAIGuardianwall Mail Security CloudAI | 13/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user… | |
| Analizada | Media (5.4) | 0.09% | — | Intel Connectivity Performance Suite | 12/5/2026 | 21/7/2026 | Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of… | |
| Aplazada | Media (5.5) | 0.47% | — | Lasuite PeopleAI | 8/5/2026 | 17/6/2026 | People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0, a user holding the Administrator role on a mail domain could send a crafted invitation request to promote any existing user (including users with no current domain access) to the Owner role. The… | |
| Aplazada | Media (4.4) | 0.30% | — | Private WP SuiteAI | 22/4/2026 | 17/6/2026 | The Private WP suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Exceptions' setting in all versions up to, and including, 0.4.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Business Process Management Suite | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Media (6.5) | 0.40% | — | Ability Accessibility SuiteAI | 16/4/2026 | 17/6/2026 | The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to SQL Injection via the 'scan_id' parameter in all versions up to, and including, 4.20. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Analizada | Alta (7) | 0.99% | — | Unisys Webperfect Image Suite | 14/4/2026 | 24/7/2026 | Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allowing remote attackers to trigger SMB connections and leak NTLMv2 machine-account hashes. Attackers… | |
| Analizada | Alta (7) | 0.88% | — | Unisys Webperfect Image Suite | 14/4/2026 | 24/7/2026 | Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a Windows UNC path as a target file argument through object-unmarshalling techniques. Attackers can… | |
| Pendiente de análisis | Crítica (9.3) | 0.10% | — | Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric MobilehmiAIMitsubishielectric Hyper HistorianAI+3 | 8/4/2026 | 24/7/2026 | Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi… | |
| Pendiente de análisis | Crítica (9.3) | 0.10% | — | Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric MobilehmiAIMitsubishielectric Hyper HistorianAI+3 | 8/4/2026 | 24/7/2026 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi… | |
| Aplazada | Media (6.5) | 0.25% | — | Totalsuite Total Poll LiteAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total Poll Lite: from n/a through <= 4.12.0. | |
| Analizada | Alta (7.1) | 0.34% | — | Salesagility Suitecrm | 5/4/2026 | 6/10/2026 | SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter in GET requests to the index.php endpoint to extract sensitive… | |
| Analizada | Alta (7.1) | 0.34% | — | Salesagility Suitecrm | 5/4/2026 | 6/10/2026 | SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection techniques to extract… | |
| Analizada | Media (6.1) | 0.25% | 💥 PoC | Interzen Zenshare Suite | 2/4/2026 | 24/7/2026 | A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter. | |
| Analizada | Media (4.3) | 0.19% | — | IBM Maximo Application Suite | 1/4/2026 | 17/6/2026 | IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and… | |
| Analizada | Alta (8.8) | 0.32% | — | Synacor Zimbra Collaboration Suite | 30/3/2026 | 17/6/2026 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the issuance of authentication tokens without CSRF protection during certain account state transitions. Specifically, tokens generated after operations such as… | |
| Analizada | Baja (3.3) | 0.14% | — | IBM Maximo Application Suite | 25/3/2026 | 17/6/2026 | IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. | |
| Aplazada | Crítica (9.9) | 0.52% | — | Totalsuite Total Poll LiteAI | 25/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.This issue affects Total Poll Lite: from n/a through <= 4.12.0. | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Codra Panorama SuiteAI | 25/3/2026 | 17/6/2026 | Please refer to security bulletin BS-035, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt . | |
| Analizada | Media (5.4) | 0.21% | — | Synacor Zimbra Collaboration Suite | 20/3/2026 | 17/6/2026 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due to improper validation of CSRF tokens. The application accepts CSRF tokens supplied within the request body instead of requiring them through the expected request header.… |