Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
506 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.38% | — | Oracle Reports Developer | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle Reports Developer.… | |
| Analizada | Media (6.8) | 0.42% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Reports Developer.… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. While… | |
| Analizada | Alta (8.8) | 0.42% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.3) | 0.35% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. While… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Reports Developer.… | |
| Analizada | Alta (7.2) | 0.34% | — | Oracle Reports Developer | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Reports Developer. While… | |
| Analizada | Alta (8.5) | 0.33% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Reports Developer. While… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer.… | |
| Analizada | Alta (7.3) | 0.35% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows low privileged attacker with network access via CORBA to compromise Oracle Reports Developer. While… | |
| Aplazada | Alta (8.1) | 0.38% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/8/2026 | 26/8/2026 | The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpdeveloper EmbedpressAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Wpdeveloper Essential BlocksAI | 6/8/2026 | 26/8/2026 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public. | |
| Aplazada | Media (5.8) | 0.33% | — | Wpdeveloper EmbedpressAI | 4/8/2026 | 26/8/2026 | The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind… | |
| Aplazada | Media (5.3) | 0.32% | — | Wpdeveloper Essential Addons FOR ElementorAI | 30/7/2026 | 30/7/2026 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are… | |
| Aplazada | Media (4.8) | 0.24% | — | Wpdeveloper Essential Addons FOR ElementorAI | 30/7/2026 | 30/7/2026 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed,… | |
| Aplazada | Media (6.5) | 0.22% | — | Wpdeveloper BetterdocsAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. |