Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
162 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.8) | 0.26% | — | Oracle Human Resources Management System | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Human Resources Management System | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this… | |
| Analizada | Baja (2.2) | 0.26% | — | Oracle Human Resources Management System | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Ireland). Successful… | |
| Analizada | Media (6.6) | 0.38% | — | Oracle Human Resources Management System | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported versions that are affected are 12.2.8-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). Successful attacks of… | |
| Analizada | Alta (8.2) | 0.35% | — | Oracle Peoplesoft Enterprise HCM Human Resources | 21/7/2026 | 3/8/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: French Public Sector Specific). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM… | |
| Analizada | Alta (7.4) | 0.36% | — | Oracle Peoplesoft Enterprise HCM Human Resources | 21/7/2026 | 3/8/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise PeopleSoft Enterprise HCM Human Resources.… | |
| Analizada | Media (6.8) | 0.29% | — | Oracle Peoplesoft Enterprise HCM Human Resources | 21/7/2026 | 3/8/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via Oracle Net to compromise PeopleSoft Enterprise HCM Human Resources.… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle JD Edwards Enterpriseone Human Resources Management | 21/7/2026 | 6/8/2026 | Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle JD Edwards Enterpriseone Human Resources Management | 21/7/2026 | 6/8/2026 | Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Human Resources Management System | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Human Resources | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks… | |
| Analizada | Alta (7.5) | 0.17% | — | Oracle Human Resources | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks require… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Human Resources Management System | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle JD Edwards Enterpriseone Human Resources Management | 17/6/2026 | 26/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Media (5.9) | 0.38% | — | Opentelemetry.resources.azure | 6/5/2026 | 17/6/2026 | OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequestor class makes HTTP requests to the Azure VM instance metadata service and reads the response body into memory without any size limit. An attacker who controls the… | |
| Analizada | Media (6.5) | 0.41% | — | Oracle Peoplesoft Enterprise HCM Human Resources | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Job Profile Manager). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Analizada | Media (5.4) | 0.17% | 💥 PoC | Oracle Peoplesoft Enterprise HCM Human Resources | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapshot). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Analizada | Alta (7.1) | 0.16% | — | Montala Resourcespace | 12/4/2026 | 17/6/2026 | ResourceSpace 8.6 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keywords parameter in collection_edit.php. Attackers can submit POST requests with crafted SQL payloads in the keywords field to extract sensitive… | |
| Analizada | Alta (8.8) | 0.42% | — | Montala Resourcespace | 5/4/2026 | 24/7/2026 | ResourceSpace 8.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'ref' parameter. Attackers can send GET requests to the watched_searches.php endpoint with crafted SQL payloads to extract sensitive database… | |
| Analizada | Media (6.1) | 0.23% | — | Oracle Peoplesoft Enterprise HCM Human Resources | 20/1/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Company Dir / Org Chart Viewer, Employee Snapshot). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.5) | 0.35% | — | Baryhuang AWS Resources MCP Server | 18/11/2025 | 17/6/2026 | A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code execution through insufficient input validation in the execute_query method. The vulnerability stems from the exposure of dangerous Python built-in functions (__import__, getattr, hasattr) in the execution… | |
| Aplazada | Media (5.1) | 0.36% | — | Bbmri-eric Biobanking AND Biomolecular Resources NegotiatorAI | 7/10/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) in Biobanking and Biomolecular Resources Negotiator v3.15.2 - European Research Infrastructure (BBMRI-ERIC), consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request using parameter text in '/api/v3/negotiations/<postUID>/posts'. This… | |
| Aplazada | Baja (2.1) | 0.25% | — | Hjsoft HCM Human Resources Management SystemAI | 10/9/2025 | 17/6/2026 | A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability is an unknown functionality of the file /templates/attestation/../../selfservice/lawresource/downlawbase. Performing manipulation of the argument ID results in sql injection. Remote exploitation of… | |
| Analizada | Media (6.1) | 0.32% | — | Infor Global Human Resources | 2/9/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Infor Global HR GHR v.11.23.03.00.21 and before allows a remote attacker to execute arbitrary code via the class parameter. |