Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2494▼ 451 respecto a la semana anterior
Críticas / altas1280▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
1620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.47% | — | Rongzhitong Visual Integrated Command AND Dispatch PlatformAI | 6/8/2026 | 12/8/2026 | A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Aplazada | Media (6.9) | 0.47% | — | Phoca CommanderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download actions lead to path traversal vulnerabilities. | |
| Aplazada | Media (5.1) | 0.44% | — | Phoca CommanderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability. | |
| Aplazada | Alta (8.8) | 0.66% | — | OnecommanderAI | 22/7/2026 | 24/7/2026 | An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component. | |
| Analizada | Alta (8.3) | 0.38% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Alta (8.8) | 0.42% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Alta (8) | 0.29% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Alta (7.6) | 0.34% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.… | |
| Aplazada | Alta (7.5) | 0.27% | — | Kyocera Command Center RXAIKyocera Taskalfa 2552ciAIKyocera Taskalfa 3252ciAIKyocera Taskalfa 2553ciAI+12 | 9/7/2026 | 10/7/2026 | Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive information can be obtained. This affects… | |
| Analizada | Baja (2.7) | 0.39% | — | Gallagher Command Centre | 7/7/2026 | 14/8/2026 | Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: | |
| Analizada | Baja (2.7) | 0.39% | — | Gallagher Command Centre | 7/7/2026 | 14/8/2026 | Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: | |
| Analizada | Media (5.3) | 0.25% | — | Gallagher Command Centre | 7/7/2026 | 18/8/2026 | An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. Version of Command Centre affected: 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.9) | 0.39% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.6) | 0.36% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Alta (8.1) | 0.38% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.9) | 0.39% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Aplazada | Baja (2.1) | 0.35% | — | Wonderwhy-er DesktopcommandermcpAI | 3/6/2026 | 22/7/2026 | A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a manipulation of the argument SearchResult[] results in inefficient regular expression complexity. It is possible to… | |
| Aplazada | Baja (2.1) | 0.22% | — | Wonderwhy-er DesktopcommandermcpAI | 3/6/2026 | 22/7/2026 | A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is… |