Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1085 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.34% | — | Oracle Webcenter Content | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Webcenter Content | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (8.4) | 0.16% | — | Oracle Webcenter Content | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Webcenter Content | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Webcenter Content | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Crítica (9.6) | 0.38% | — | Oracle Webcenter Content | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (8.7) | 0.34% | — | Oracle Webcenter Content | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Aplazada | Media (6.5) | 0.22% | — | Table OF Contents BlockAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | If-so Dynamic Content PersonalizationAI | 13/8/2026 | 14/8/2026 | Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | |
| Aplazada | Crítica (9.8) | 0.91% | — | AI Copilot Content GeneratorAI | 8/8/2026 | 12/8/2026 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new… | |
| Aplazada | Alta (8.1) | 0.39% | — | Contentviewspro Content ViewsAI | 7/8/2026 | 26/8/2026 | The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks. | |
| Aplazada | Alta (8.1) | 1.2% | — | Keywordrush Content EGGAI | 5/8/2026 | 12/8/2026 | The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post metadata: the value passes only through… | |
| Aplazada | Crítica (9.8) | 0.84% | — | Elearningfreak Insert OR Embed Articulate ContentAI | 3/8/2026 | 26/8/2026 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers… | |
| Aplazada | Media (5.3) | 0.31% | — | Code-atlantic Content ControlAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. | |
| Aplazada | Media (6.5) | 0.45% | — | AI Copilot Content GeneratorAI | 23/7/2026 | 23/7/2026 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Content Manager | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager. Successful attacks… | |
| Analizada | Alta (8.8) | 0.21% | — | Oracle Webcenter Content | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Content | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (7.5) | 0.16% | — | Oracle Webcenter Content | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (7.7) | 0.26% | — | Oracle Webcenter Content | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Content | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Content | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Content | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Webcenter Content | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (8) | 0.35% | — | Oracle Webcenter Content | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content.… |