Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 0.34% | — | Oracle Agile Product Lifecycle Management | 21/7/2026 | 25/8/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Agile Product Lifecycle Management | 21/7/2026 | 25/8/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Agile Product Lifecycle Management | 21/7/2026 | 25/8/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Agile Product Lifecycle Management | 21/7/2026 | 25/8/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can… | |
| Analizada | Media (6.5) | 0.15% | — | Oracle Agile Product Lifecycle Management | 21/7/2026 | 25/8/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. While the… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Agile Product Lifecycle Management | 21/7/2026 | 25/8/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Agile Product Lifecycle Management | 21/7/2026 | 25/8/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Agile Product Lifecycle Management | 21/7/2026 | 25/8/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability… | |
| Analizada | Media (6.5) | 0.39% | — | Oracle Agile Product Lifecycle Management | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human… | |
| Analizada | Alta (7.5) | 0.55% | — | IBM Engineering Lifecycle Management | 17/7/2026 | 11/8/2026 | IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion. | |
| Aplazada | Alta (7.1) | 0.25% | — | Kids LifeAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions. | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Agile Product Lifecycle Management | 17/6/2026 | 25/8/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result… | |
| Aplazada | Media (5.3) | 0.22% | — | Awplife Event MonsterAI | 6/6/2026 | 23/7/2026 | The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 2.1.0. This is due to the capture_payment() AJAX handler (registered via wp_ajax_nopriv_em_capture_payment) trusting client-supplied… | |
| Pendiente de análisis | Baja (3.3) | 0.10% | — | HCL Bigfix Cloud Lifecycle ManagementAI | 4/6/2026 | 22/7/2026 | HCL BigFix Cloud Lifecycle Management is affected by lack of input validation. This low-level flaw allows unauthorized access and may lead to information exposure. | |
| Aplazada | Media (6.1) | 0.15% | — | Transsion AiassistantlifestyleAI | 2/6/2026 | 22/7/2026 | Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all versions on Android allows remote attacker to execute arbitrary JavaScript in the WebView context via crafted web_action_data URL parameter. | |
| Analizada | Alta (7.2) | 0.50% | — | IBM Engineering Lifecycle Management | 26/5/2026 | 24/7/2026 | IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted. | |
| Analizada | Crítica (9.8) | 0.59% | — | IBM Engineering Lifecycle Management | 26/5/2026 | 24/7/2026 | IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application. | |
| Analizada | Alta (7.1) | 0.41% | — | IBM Engineering Lifecycle Management | 26/5/2026 | 24/7/2026 | IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix 021, 7.1.0 Interim Fix 001 through Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to… | |
| Pendiente de análisis | Media (5.3) | 0.60% | — | Outsystems LifetimeAI | 25/5/2026 | 11/8/2026 | OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application. This issue was fixed in OutSystems Lifetime version… | |
| Aplazada | Alta (7.2) | 0.40% | — | LifepressAI | 12/5/2026 | 17/6/2026 | The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_mds AJAX action in all versions up to, and including, 2.2.2. This is due to the `wp_ajax_nopriv_lp_update_mds` action being registered without nonce verification or capability checks, combined with… | |
| Aplazada | Alta (7.1) | 0.93% | — | Lifesize ClearseaAI | 29/4/2026 | 17/6/2026 | LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interface. Attackers can exploit the upload endpoint with directory traversal sequences to write files to arbitrary locations on… | |
| Modificada | Media (4.8) | 0.19% | — | IBM Guardium KEY Lifecycle Manager | 23/4/2026 | 17/6/2026 | IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthorized users to perform administrative operations after being demoted. Attackers could access sensitive data, modify system configurations, or change permissions for other users. The issue undermines… | |
| Analizada | Media (6.5) | 0.27% | — | Oracle Life Sciences Inform | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: App Server). Supported versions that are affected are 7.0.1.0 and 7.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences InForm.… | |
| Analizada | Media (6.3) | 0.24% | — | Oracle Life Sciences Inform | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: IDM Authentication). Supported versions that are affected are 7.0.1.0 and 7.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences… | |
| Analizada | Media (4.3) | 0.30% | — | Oracle Agile Product Lifecycle Management FOR Process | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile… |