Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

1385 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8)0.38%—Oracle Communications Converged Application Server21/7/20266/8/2026
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with network access via TLS to compromise Oracle Communications Converged…
AnalizadaCrítica (9)0.39%—Oracle Communications Converged Application Server21/7/20266/8/2026
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications…
AnalizadaMedia (6.4)0.31%—Oracle Communications Convergent Charging Controller21/7/202617/8/2026
Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions that are affected are 15.0.0.0.0 and 15.2.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
AnalizadaAlta (8.8)0.43%—Oracle Communications Service Catalog AND Design21/7/20266/8/2026
Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solution Designer). Supported versions that are affected are 8.0.0.7.0-8.3.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
AnalizadaAlta (7.8)0.16%—Oracle Communications Billing AND Revenue Management21/7/202617/8/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform). Supported versions that are affected are 15.0.0.0.0-15.0.1.0.0 and 15.1.0.0.0-15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure…
AnalizadaAlta (7.1)0.30%—Oracle Communications Unified Inventory Management21/7/202617/8/2026
Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security). Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and 8.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
AnalizadaAlta (7.8)0.16%—Oracle Communications Billing AND Revenue Management21/7/202617/8/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: BRM Server). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the…
AnalizadaAlta (7.8)0.16%—Oracle Communications Billing AND Revenue Management Elastic Charging Engine21/7/202619/8/2026
Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Diameter Gateway and SDK). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the…
AnalizadaAlta (8.1)0.36%—Oracle Telecommunications Billing Integrator21/7/202629/7/2026
Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
AnalizadaAlta (7.3)0.15%—Oracle Communications Pricing Design Center21/7/202631/7/2026
Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the…
AplazadaCrítica (9.8)0.47%—Turkmesh Communication Services INC Turkhotspot 5651 LoglamaAI21/7/202621/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This issue affects Turkhotspot 5651 Loglama: from 5.1.2 before 5.1.3.
Pendiente de análisisAlta (8.2)0.22%—Allen Bradley Compactlogix 5380AIAllen Bradley Controllogix 5580AIAllen Bradley EN4 Communication ModuleAI14/7/202614/7/2026
A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a…
AplazadaAlta (8.5)0.36%—Thememove UnicampAI2/7/20266/10/2026
Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
AplazadaMedia (6)0.24%—Shenzhen Liandian Communication Technology V380 IP CameraAI18/6/202622/6/2026
A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the device’s credential-enforced live-view workflow and directly retrieve real-time video stream data.
AnalizadaAlta (8.6)88%⚠ Explotación activa💥 PoCCisco Unified Communications Manager3/6/202622/7/2026
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to…
AplazadaAlta (8.1)0.52%—Ancorathemes UnicaAIPHPAI25/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Unica unica allows PHP Local File Inclusion.This issue affects Unica: from n/a through <= 1.4.1.
ModificadaMedia (5.4)0.17%—Hcltech Unica19/3/202617/6/2026
A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data within its later HTTP responses in an unsafe…
AnalizadaMedia (6.1)0.16%—Hcltech UnicaHcltech Unica Audience CentralHcltech Unica CampaignHcltech Unica Centralised Offer Management+517/3/202617/6/2026
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in…
AnalizadaCrítica (9.8)0.28%—Hcltech UnicaHcltech Unica Audience Central16/3/202617/6/2026
Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently depending on whether the injected condition…
AnalizadaAlta (7.5)0.48%—Fortinet Fortisoar Agent Communication Bridge10/3/202617/6/2026
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar user on a…
AplazadaMedia (5.3)0.25%—Doruk Communication AND Automation Industry AND Trade INC WispotterAI18/2/202617/6/2026
Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication and Automation Industry and Trade Inc. Wispotter allows Password Brute Forcing, Brute Force. This issue affects Wispotter: from 1.0 before v2025.10.08.1.
AplazadaAlta (7.5)0.35%—Thememove UnicampAI3/2/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.This issue affects Unicamp: from n/a through <= 2.7.1.
AplazadaCrítica (9.8)0.47%💥 PoCEmit Informatics AND Communication Technologies Digita Efficiency Management SystemAI3/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies Industry and Trade Ltd. Co. DIGITA Efficiency Management System allows SQL Injection. This issue affects DIGITA Efficiency Management System: through 03022026. NOTE: The…
AplazadaMedia (5.1)0.59%—Altitude Authentication ServiceAIAltitude Communication ServerAI26/1/202617/6/2026
Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior…
AplazadaMedia (6.9)0.43%—Altitude Communication ServerAI26/1/202617/6/2026
Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of multiple HTTP requests over a single Keep-Alive connection using Content-Length headers. This can cause a desynchronization of requests between frontend and backend servers, which could allow request…