Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Enterprise Capture | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Enterprise Capture | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Aplazada | Crítica (9.1) | 0.86% | — | Ammos Instrument Toolkit Binary Stream CaptureAINasa AIT CoreAI | 21/7/2026 | 23/7/2026 | The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing for instrument and CubeSat Missions. In… | |
| Aplazada | Alta (7.1) | 0.47% | — | Samsung CaptureAI | 15/7/2026 | 16/7/2026 | PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Capture objects running within the same Python process could share state, including HTTP headers, cookies, browser storage, HTTP credentials, proxy… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter… | |
| Analizada | Crítica (10) | 0.51% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3 to compromise Oracle WebCenter… | |
| Analizada | Crítica (10) | 0.51% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 26/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Enterprise Capture | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter… | |
| Analizada | Media (6.6) | 0.54% | — | Lookyloo Playwright Capture | 13/5/2026 | 17/6/2026 | PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not sufficiently restrict navigations and resource requests initiated by rendered pages. An attacker-controlled page could abuse browser-side redirection mechanisms, such as window.location.href, to make the… | |
| Pendiente de análisis | Crítica (9.3) | 0.88% | 💥 PoC | Kofax CaptureAIKofax Tungsten CaptureAI | 23/4/2026 | 17/6/2026 | Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a default, publicly known endpoint identifier. An unauthenticated remote… | |
| Aplazada | Crítica (9.8) | 1.8% | 💥 Exploit | Rymera WEB CO PTY LTD Woocommerce Wholesale Lead CaptureAI | 19/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1. |