Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
9650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.16% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks require human… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized… | |
| Analizada | Alta (7.1) | 0.28% | — | Oracle E-business Suite | 18/8/2026 | 3/9/2026 | Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Irecruitment | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle E-business Suite | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Call Center Technology.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle E-business Suite | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle E-business Suite | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology.… | |
| Analizada | Alta (8.5) | 0.30% | — | Oracle E-business Suite | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology.… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle E-business Suite | 18/8/2026 | 3/9/2026 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle E-business Suite | 18/8/2026 | 3/9/2026 | Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle U.S. Federal Financials.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle SOA Suite | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Commerce Guided Search | 18/8/2026 | 23/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (9.3) | 0.38% | — | Oracle Commerce Guided Search | 18/8/2026 | 23/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Commerce Guided Search | 18/8/2026 | 23/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle E-business Suite | 18/8/2026 | 30/9/2026 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle E-business Suite | 18/8/2026 | 23/9/2026 | Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet… | |
| Pendiente de análisis | Crítica (9.1) | 3.2% | 💥 Exploit | Redhat KeycloakAIRedhat Build OF KeycloakAI | 18/8/2026 | 8/9/2026 | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email… | |
| Aplazada | Alta (8.5) | 0.48% | — | Codewhale TUIAI | 18/8/2026 | 8/9/2026 | CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with --output= is interpreted as a git flag.… | |
| Aplazada | Alta (8.5) | 0.36% | — | CodewhaleAICodewhale-tuiAI | 18/8/2026 | 8/9/2026 | CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine treats as 'never prompt,' causing arbitrary model-supplied Python code to run in a… | |
| Aplazada | Media (4.3) | 0.25% | — | Wptablebuilder WP Table BuilderAI | 18/8/2026 | 20/8/2026 | Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Duitku Payment GatewayAI | 18/8/2026 | 20/8/2026 | Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mdmag Quill FormsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. |