Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
1243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.25% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Database Server | 21/7/2026 | 6/8/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is… | |
| Analizada | Media (6.5) | 0.37% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where… | |
| Analizada | Media (4.3) | 0.37% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.… | |
| Analizada | Media (5.7) | 0.15% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database… | |
| Analizada | Media (4.3) | 0.30% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.… | |
| Analizada | Media (5.6) | 0.13% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database… | |
| Analizada | Media (6.7) | 0.18% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database… | |
| Analizada | Baja (3.8) | 0.15% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database… | |
| Analizada | Media (6.5) | 0.42% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.… | |
| Analizada | Media (6.5) | 0.42% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.… | |
| Analizada | Media (6.5) | 0.15% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Database Server | 21/7/2026 | 6/8/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. Successful… | |
| Analizada | Media (5.6) | 0.24% | — | Oracle Database Server | 21/7/2026 | 6/8/2026 | Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JDBC executes to… | |
| Analizada | Media (6.5) | 0.32% | — | Oracle Database Server | 21/7/2026 | 6/8/2026 | Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise JDBC. Successful attacks require human interaction from a… | |
| Analizada | Alta (8.2) | 0.41% | — | Oracle Database Server | 21/7/2026 | 6/8/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in unauthorized ability… | |
| Analizada | Media (6.8) | 0.40% | — | Oracle Database Server | 21/7/2026 | 6/8/2026 | Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise JDBC. Successful attacks require… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Database Server | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of… | |
| Analizada | Media (6.5) | 0.30% | — | Oracle Database Server | 21/7/2026 | 6/8/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. Successful… | |
| Analizada | Baja (2.7) | 0.29% | — | Oracle Database Server | 21/7/2026 | 6/8/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this… | |
| Analizada | Media (5.8) | 0.30% | — | Oracle Database Server | 21/7/2026 | 6/8/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may… | |
| Analizada | Alta (8.6) | 0.18% | — | Google MCP Toolbox FOR Databases | 21/7/2026 | 22/9/2026 | A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and interpolates them unescaped via… | |
| Pendiente de análisis | Baja (3.7) | 0.35% | — | SAP Hana DatabaseAI | 14/7/2026 | 14/7/2026 | SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low… | |
| Aplazada | Media (5) | 0.22% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 13/7/2026 | 13/7/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field value, allowing unauthenticated users to inject arbitrary PHP objects that are instantiated when an administrator views the stored entry.… |