Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.43% | — | Oracle Weblogic Server | 17/6/2026 | 18/6/2026 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. Successful attacks of this… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Weblogic Server | 17/6/2026 | 18/6/2026 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise WebLogic Server. While the… | |
| Analizada | Crítica (10) | 0.51% | — | Oracle Weblogic Server | 17/6/2026 | 18/6/2026 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in… | |
| Analizada | Media (6.6) | 0.38% | — | Oracle Weblogic Server | 17/6/2026 | 18/6/2026 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise WebLogic Server. Successful attacks of this… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Weblogic Server | 17/6/2026 | 18/6/2026 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in… | |
| Analizada | Alta (8.8) | 0.42% | — | Oracle Weblogic Server | 17/6/2026 | 18/6/2026 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise WebLogic Server. Successful attacks require… | |
| Analizada | Alta (8.7) | 0.33% | — | Oracle Weblogic Server | 17/6/2026 | 18/6/2026 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise WebLogic Server. Successful attacks require… | |
| Analizada | Media (6.5) | 0.32% | — | Oracle Weblogic Server | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (7.5) | 0.44% | — | Oracle Weblogic Server | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Weblogic Server | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks… | |
| Aplazada | Alta (8.1) | 0.57% | — | Solverwp EleblogAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SolverWp Eleblog – Elementor Blog And Magazine Addons ele-blog allows PHP Local File Inclusion.This issue affects Eleblog – Elementor Blog And Magazine Addons: from n/a through <= 2.0.3. | |
| Analizada | Crítica (10) | 73% | ⚠ Explotación activa | Oracle Http ServerOracle Weblogic Server Proxy Plug-in | 20/1/2026 | 25/8/2026 | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable… | |
| Analizada | Media (6.5) | 0.26% | — | Perfreeblog | 30/10/2025 | 17/6/2026 | PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachController.java). | |
| Modificada | Crítica (9.8) | 0.49% | — | Zhyd Oneblog | 28/10/2025 | 17/6/2026 | zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. | |
| Modificada | Alta (7.6) | 0.27% | — | Perfreeblog | 24/10/2025 | 5/7/2026 | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function | |
| Modificada | Alta (7.6) | 0.27% | — | Perfreeblog | 24/10/2025 | 5/7/2026 | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function | |
| Modificada | Alta (7.6) | 0.29% | — | Perfreeblog | 24/10/2025 | 5/7/2026 | PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function | |
| Modificada | Media (5.3) | 0.32% | — | Perfreeblog | 24/10/2025 | 5/7/2026 | PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function | |
| Analizada | Media (5.3) | 0.26% | — | Oracle Weblogic Server | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.… | |
| Analizada | Alta (7.5) | 0.40% | — | Oracle Weblogic Server | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle WebLogic Server. Successful attacks… | |
| Analizada | Alta (7.5) | 0.40% | — | Zhyd Oneblog | 16/9/2025 | 17/6/2026 | The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability. | |
| Analizada | Alta (7.5) | 0.36% | — | Perfreeblog | 25/8/2025 | 17/6/2026 | PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function. | |
| Analizada | Alta (7.5) | 0.91% | — | Perfreeblog | 25/8/2025 | 17/6/2026 | PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function. | |
| Analizada | Baja (2.1) | 0.33% | — | Fabian Eblog Site | 11/8/2025 | 17/6/2026 | A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/save-slider.php of the component File Upload Module. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.1) | 0.26% | — | Oracle Weblogic Server | 15/7/2025 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.… |