Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

8598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.51%—Oracle Commerce Platform18/8/20261/9/2026
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks…
AnalizadaCrítica (9.8)0.51%—Oracle Commerce Platform18/8/20261/9/2026
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Platform. Successful attacks…
AnalizadaAlta (7.3)0.16%—Oracle Service Delivery Platform Number Portability18/8/202628/8/2026
Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SDP Number Portability executes…
AnalizadaAlta (7.5)0.41%—Oracle Service Delivery Platform Number Portability18/8/202628/8/2026
Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SDP Number Portability.…
AnalizadaAlta (8.1)0.39%—Oracle Applications Platform Engineering18/8/202628/8/2026
Vulnerability in the Oracle Applications Platform Engineering product of Oracle E-Business Suite (component: Valid Session). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Applications…
AnalizadaAlta (8.1)0.39%—Oracle Enterprise Manager Base Platform18/8/202626/8/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager…
AnalizadaAlta (7.8)0.16%—Oracle Enterprise Manager Base Platform18/8/202626/8/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base…
AnalizadaMedia (5.6)0.13%—Oracle Enterprise Manager Base Platform18/8/202626/8/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise…
AnalizadaAlta (8.6)0.37%—Oracle Enterprise Manager Base Platform18/8/202626/8/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager…
AnalizadaAlta (8.8)0.43%—Oracle Enterprise Manager Base Platform18/8/202626/8/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Config Console). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise…
AnalizadaMedia (6.5)0.27%—Oracle Service Delivery Platform18/8/202621/8/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful…
AnalizadaMedia (6.8)0.40%—Oracle Service Delivery Platform18/8/202621/8/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Service Delivery Platform.…
AnalizadaCrítica (9.6)0.36%—Oracle Service Delivery Platform18/8/202621/8/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Service Delivery…
AnalizadaAlta (8.7)0.36%—Oracle Service Delivery Platform18/8/202621/8/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Service Delivery Platform.…
AplazadaAlta (8.8)0.56%💥 PoCBrainstormforce SureformsAI18/8/20263/9/2026
CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is…
AplazadaAlta (7.5)0.58%💥 PoCBrainstormforce SureformsAI18/8/20263/9/2026
The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface,…
AplazadaMedia (4.3)0.25%—Romethemeform FOR ElementorAI18/8/202620/8/2026
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
AplazadaMedia (6.5)0.29%—Supsystic Contact FormAI18/8/202620/8/2026
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
AplazadaAlta (7.1)0.25%—Supsystic Contact FormAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
AplazadaMedia (6.5)0.22%—Wpzoom Forms Contact Form Plugin FOR GutenbergAI18/8/202620/8/2026
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
AplazadaAlta (7.1)0.25%—Fluentforms Fluent Forms PRO ADD ON PackAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
AplazadaAlta (8.5)0.36%—Gravityforms BookingsAI18/8/202620/8/2026
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
AplazadaAlta (7.5)0.39%—FormychatAI18/8/202620/8/2026
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
AplazadaAlta (7.1)0.25%—Mdmag Quill FormsAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
Pendiente de análisisCrítica (9.6)0.35%—Redhat Ansible Automation PlatformAIHashicorp VaultAI18/8/202624/9/2026
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role…