Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.30% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Media (6.2) | 0.17% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Commerce Platform | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful… | |
| Analizada | Alta (7.3) | 0.31% | — | Oracle Commerce Platform | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Commerce Platform | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful… | |
| Analizada | Media (6.8) | 0.29% | — | Oracle Commerce Platform | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks… | |
| Analizada | Alta (7.5) | 0.44% | — | Oracle Commerce Platform | 21/7/2026 | 12/8/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Commerce Platform. Successful attacks… | |
| Analizada | Alta (7.6) | 0.15% | — | Oracle Commerce Platform | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Commerce Platform | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Commerce Platform | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Commerce Platform | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Commerce Service Center | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center. Successful… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | HCL CommerceAI | 20/7/2026 | 21/7/2026 | HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations. | |
| Aplazada | Media (5.1) | 0.38% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 19/7/2026 | 20/7/2026 | A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely. | |
| Aplazada | Alta (7.5) | 0.42% | — | Ikas Technology INC E-commerceAI | 17/7/2026 | 17/7/2026 | Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026. | |
| Aplazada | Media (5.4) | 0.29% | — | WPS Bookings FOR WoocommerceAI | 17/7/2026 | 17/7/2026 | The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders. | |
| Aplazada | Media (6.1) | 0.39% | — | Woocommerce Placetopay GatewayAIPlacetopay Avalplay GatewayAI | 17/7/2026 | 17/7/2026 | The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.4) | 0.34% | — | Sysbasics Customize MY Account FOR WoocommerceAI | 16/7/2026 | 17/7/2026 | The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter in all versions up to, and including, 4.4.14 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.43% | 💥 PoC | Cusrev Customer Reviews FOR WoocommerceAI | 16/7/2026 | 16/7/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to upload media files (bounded to an image and video allowlist)… | |
| Aplazada | Alta (8.1) | 0.38% | — | Tychesoftwares Abandoned Cart Lite FOR WoocommerceAI | 16/7/2026 | 16/7/2026 | The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled. |