Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Portal | 15/9/2026 | 23/9/2026 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Webcenter Portal | 15/9/2026 | 23/9/2026 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Portal | 15/9/2026 | 23/9/2026 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Portal | 15/9/2026 | 23/9/2026 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Portal | 15/9/2026 | 23/9/2026 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Portal | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Portal | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful… | |
| Analizada | Crítica (9.3) | 0.38% | — | Oracle Webcenter Portal | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Portal | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Portal | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Webcenter Portal | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Webcenter Portal | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Portal | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Portal | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the… | |
| Aplazada | Alta (8.1) | 0.35% | — | Nl.nl-portal TaakAI | 11/9/2026 | 30/9/2026 | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to verify ownership when processing the `submitTaakV2` GraphQL mutation, allowing an… | |
| Aplazada | Media (6.5) | 0.34% | — | Nl.nl-portal Documenten-apiAINl.nl-portal BesluitenAI | 11/9/2026 | 30/9/2026 | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from version 1.5.0 through 3.0.0 lack per-user… | |
| Aplazada | Media (5.3) | 0.40% | — | NL Portal Backend LibrariesAI | 11/9/2026 | 30/9/2026 | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and including 3.0.0, deployments using the shipped default configuration exposed two GraphQL developer features without requiring… | |
| Aplazada | Alta (7.5) | 0.30% | — | Menulux Software INC Menulux PortalAI | 4/9/2026 | 8/9/2026 | Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448. | |
| Aplazada | Alta (7.1) | 0.21% | — | Menulux Software INC Menulux PortalAI | 4/9/2026 | 8/9/2026 | Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20260903211448. | |
| Aplazada | Media (4.3) | 0.20% | — | Menulux Software INC Menulux PortalAI | 4/9/2026 | 8/9/2026 | Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Portal: before 20260903211448. | |
| Aplazada | Media (5.4) | 0.16% | — | Menulux Software INC Menulux PortalAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue affects Menulux Portal: before 20260903211448. | |
| Aplazada | Media (6.3) | 0.18% | — | PIK Online Software Solutions INC PIK Online PortalAI | 4/9/2026 | 8/9/2026 | Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis. This issue affects Pik Online Portal: through 3.5.1. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpjobportal WP JOB PortalAI | 28/8/2026 | 28/8/2026 | Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions. | |
| Pendiente de análisis | Crítica (9.1) | 0.53% | — | Zscaler Client ConnectorAIZscaler Client Connector PortalAI | 24/8/2026 | 28/8/2026 | An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. | |
| Analizada | Media (4.8) | 0.24% | — | Esri Portal FOR Arcgis | 21/8/2026 | 11/9/2026 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to… |