Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2286 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.49%—Cmsjunkie J-businessdirectory19/6/202619/8/2026
Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter. Attackers can send GET requests to index.php with the…
AplazadaAlta (8.8)0.48%—Pixel Makers Creative Entrepreneur Booking FOR Small BusinessesAI17/6/20266/10/2026
Deserialization of Untrusted Data vulnerability in Pixel Makers Creative INC. Entrepreneur - Booking for Small Businesses WordPress Theme allows Object Injection. This issue affects Entrepreneur - Booking for Small Businesses WordPress Theme: from n/a before 3.1.5.
AnalizadaAlta (8.1)0.36%—Oracle E-business Suite17/6/202617/8/2026
Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Configure to Order.…
AplazadaCrítica (9.9)0.48%—Wp-businessdirectoryAI15/6/202617/6/2026
Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
AplazadaMedia (5.5)0.11%—Avast AntivirusAIAVG AntivirusAINorton AntivirusAIAvast ONEAI+112/6/20267/10/2026
Stack overflow vulnerability in Avast Antivirus when scanning a malformed Office Open XML file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds…
AplazadaAlta (7.8)0.15%—Avast AntivirusAIAVG AntivirusAINorton AntivirusAIAvast ONEAI+112/6/20267/10/2026
Heap out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed zip file containing XML may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and…
AplazadaMedia (5.5)0.11%—Avast AntivirusAIAVG AntivirusAINorton AntivirusAIAvast ONEAI+112/6/20267/10/2026
Stack overflow vulnerability due to uncontrolled recursion in Avast Antivirus when scanning a malformed PDF file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus…
AplazadaAlta (7.8)0.15%—Avast AntivirusAIAVG AntivirusAINorton AntivirusAIAvast ONEAI+112/6/20267/10/2026
Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and…
AplazadaAlta (7.8)0.15%—Avast AntivirusAIAVG AntivirusAINorton AntivirusAIAvast ONEAI+112/6/20267/10/2026
Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE file with .NET metadata may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on…
AplazadaMedia (5.5)0.11%—Avast AntivirusAIAVG AntivirusAINorton AntivirusAIAvast ONEAI+112/6/20267/10/2026
Use of stack memory after free vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition…
AplazadaMedia (5.5)0.11%—Avast AntivirusAIAVG AntivirusAINorton AntivirusAIAvast ONEAI+112/6/20267/10/2026
Uncontrolled recursion vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds…
AplazadaAlta (7.8)0.15%—Avast AntivirusAIAVG AntivirusAINorton AntivirusAIAvast ONEAI+112/6/20267/10/2026
Heap buffer out-of-bounds write vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and…
Pendiente de análisisMedia (4.3)0.15%—SAP Business Objects Business Intelligence PlatformAI9/6/202623/7/2026
SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by authenticated users, resulting in an email spoofing vulnerability.This vulnerability has a low impact on integrity and does not affect the confidentiality and availability of the application.
Pendiente de análisisBaja (3.7)0.30%—SAP Business ObjectsAI9/6/202623/7/2026
Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application leaks sensitive information .This has a low impact on the confidentiality of the data. There is no impact on integrity and availability of the application.
AnalizadaAlta (7.8)0.12%—Synology Active Backup FOR Business Recovery Media Creator3/6/202622/7/2026
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
AplazadaMedia (6.4)0.16%—Automotive CAR Dealership BusinessAI29/5/202621/7/2026
The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom field in Portfolio Items in all versions up to, and including, 13.4.1. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the…
AnalizadaAlta (8.8)0.43%—Oracle E-business Suite28/5/202621/7/2026
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Flow Manufacturing. Successful attacks of…
AnalizadaAlta (8.1)0.36%—Oracle E-business Suite28/5/202621/7/2026
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this…
AnalizadaAlta (8.8)0.43%—Oracle E-business Suite28/5/202621/7/2026
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this…
AnalizadaAlta (8.8)0.43%—Oracle E-business Suite28/5/202621/7/2026
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Payroll. Successful attacks of this…
AnalizadaCrítica (9.1)0.43%—Oracle E-business Suite28/5/202621/7/2026
Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet…
AnalizadaAlta (7.4)0.34%—Oracle E-business Suite28/5/202621/7/2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Payments. Successful attacks of this…
AnalizadaCrítica (9.8)0.81%⚠ Explotación activa💥 PoCOracle E-business Suite28/5/202621/7/2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this…
AnalizadaMedia (4.3)0.22%—IBM Business Automation Workflow27/5/202617/6/2026
IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.
AnalizadaMedia (5.6)0.09%—Synology Active Backup FOR Business Agent27/5/20267/10/2026
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.