Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
8598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Commerce Platform | 18/8/2026 | 1/9/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Commerce Platform | 18/8/2026 | 1/9/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Platform. Successful attacks… | |
| Analizada | Alta (7.3) | 0.16% | — | Oracle Service Delivery Platform Number Portability | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SDP Number Portability executes… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Service Delivery Platform Number Portability | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SDP Number Portability.… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Applications Platform Engineering | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Applications Platform Engineering product of Oracle E-Business Suite (component: Valid Session). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Applications… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base… | |
| Analizada | Media (5.6) | 0.13% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise… | |
| Analizada | Alta (8.6) | 0.37% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Config Console). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise… | |
| Analizada | Media (6.5) | 0.27% | — | Oracle Service Delivery Platform | 18/8/2026 | 21/8/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful… | |
| Analizada | Media (6.8) | 0.40% | — | Oracle Service Delivery Platform | 18/8/2026 | 21/8/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Service Delivery Platform.… | |
| Analizada | Crítica (9.6) | 0.36% | — | Oracle Service Delivery Platform | 18/8/2026 | 21/8/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Service Delivery… | |
| Analizada | Alta (8.7) | 0.36% | — | Oracle Service Delivery Platform | 18/8/2026 | 21/8/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Service Delivery Platform.… | |
| Aplazada | Alta (8.8) | 0.56% | 💥 PoC | Brainstormforce SureformsAI | 18/8/2026 | 3/9/2026 | CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is… | |
| Aplazada | Alta (7.5) | 0.58% | 💥 PoC | Brainstormforce SureformsAI | 18/8/2026 | 3/9/2026 | The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface,… | |
| Aplazada | Media (4.3) | 0.25% | — | Romethemeform FOR ElementorAI | 18/8/2026 | 20/8/2026 | Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. | |
| Aplazada | Media (6.5) | 0.29% | — | Supsystic Contact FormAI | 18/8/2026 | 20/8/2026 | Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Supsystic Contact FormAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpzoom Forms Contact Form Plugin FOR GutenbergAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Gravityforms BookingsAI | 18/8/2026 | 20/8/2026 | Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | FormychatAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mdmag Quill FormsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | |
| Pendiente de análisis | Crítica (9.6) | 0.35% | — | Redhat Ansible Automation PlatformAIHashicorp VaultAI | 18/8/2026 | 24/9/2026 | A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role… |