Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
443 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.7) | 0.14% | — | Oracle Applications Technology Stack | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Applications Technology… | |
| Analizada | Media (6.5) | 0.15% | — | Oracle Applications DBA | 21/7/2026 | 5/8/2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Applications DBA executes to… | |
| Analizada | Media (4.6) | 0.21% | — | Oracle Applications Framework | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Applications Framework | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Applications Framework | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Applications Technology Stack | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications… | |
| Analizada | Media (6.5) | 0.27% | — | Oracle Applications Manager | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications… | |
| Analizada | Media (4.3) | 0.36% | — | Spaceapplications Yamcs | 16/7/2026 | 20/7/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omitted specific packet names: with an empty name list the… | |
| Analizada | Crítica (9.1) | 1.1% | — | Spaceapplications Yamcs | 16/7/2026 | 20/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase… | |
| Analizada | Crítica (9.8) | 0.98% | — | Spaceapplications Yamcs | 16/7/2026 | 20/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a ClassFilter, so a user with the ChangeMissionDatabase privilege could… | |
| Analizada | Crítica (9.1) | 1.1% | — | Spaceapplications Yamcs | 16/7/2026 | 17/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino compiler without… | |
| Analizada | Crítica (9.8) | 2.1% | 💥 Exploit | Spaceapplications Yamcs | 16/7/2026 | 17/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform… | |
| Modificada | Media (4.3) | 1.1% | 💥 Exploit | Spaceapplications Yamcs | 16/7/2026 | 18/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one with low or no… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Applications Manager | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Manager. While… | |
| Aplazada | Media (4.3) | 1.0% | 💥 Exploit | Spaceapplications YamcsAI | 10/6/2026 | 21/7/2026 | Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13.0 and 5.12.7 patch… | |
| Analizada | Media (6.9) | 0.46% | — | KJD Internationalized Domain Names IN Applications | 5/6/2026 | 23/7/2026 | Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `"\u0660" * N` or `"\u30fb" * N + "\u6f22"` utilize the `valid_contexto` function prior to… | |
| Analizada | Media (6.5) | 7.1% | ⚠ Explotación activa💥 Exploit | Encode StarletteRedhat AI Inference ServerRedhat Ansible Automation PlatformRedhat Migration Toolkit FOR Applications+4 | 26/5/2026 | 1/10/2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make… | |
| Aplazada | Alta (7.5) | 0.41% | — | Meari Client ApplicationsAIMeari CloudedgeAIMeari ArentiAI | 11/5/2026 | 17/6/2026 | In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x), the integrated call path to openapi-euce.mearicloud.com can be abused to retrieve WAN IP data for arbitrary devices. The root cause is a server-side authorization… | |
| Analizada | Media (6.8) | 0.14% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with logon to the… | |
| Analizada | Media (4.8) | 0.25% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Difficult to exploit vulnerability allows low privileged attacker with network… | |
| Modificada | Media (6.8) | 0.29% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Difficult to exploit vulnerability allows low privileged attacker with network access via… | |
| Analizada | Media (6.5) | 0.39% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Media (4.7) | 0.29% | — | Oracle Applications Framework | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Alta (7.6) | 0.30% | 💥 PoC | Oracle Applications DBA | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks… |