Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.33% | — | Oracle Sales | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales. Successful attacks of this… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Sales | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Sales | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales. Successful attacks of this… | |
| Aplazada | Alta (7.5) | 0.58% | — | Object Sync FOR SalesforceAI | 15/8/2026 | 20/8/2026 | The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route's permission callback (can_process()) checks only the HTTP method for the push class — no capability or nonce — so it is… | |
| Aplazada | Alta (7.5) | 0.35% | — | Storegrowth Smart Sales Booster FOR WoocommerceAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. | |
| Aplazada | Media (5.3) | 0.40% | — | Storegrowth Sales BoosterAI | 28/7/2026 | 28/7/2026 | The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the bogo_category_msg_create() AJAX handler, which is registered for both authenticated (wp_ajax_) and unauthenticated (wp_ajax_nopriv_) users… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Telesales | 21/7/2026 | 29/7/2026 | Vulnerability in the TeleSales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise TeleSales. Successful attacks of this vulnerability can… | |
| Analizada | Media (6.3) | 0.26% | — | Oracle Sales FOR Handhelds | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Outlook Sync Win 32). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales for Handhelds. Successful… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Telesales | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle TeleSales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle TeleSales. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Telesales | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle TeleSales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle TeleSales. Successful attacks of this… | |
| Analizada | Alta (8) | 0.38% | — | Oracle Sales Offline | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Sales Offline. While the… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Sales Offline | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of… | |
| Analizada | Alta (8.3) | 0.39% | — | Oracle Sales Offline | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Sales Offline | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of… | |
| Analizada | Media (4.8) | 0.12% | — | Victorkane Salesforce Suite | 10/7/2026 | 6/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3. | |
| Aplazada | Alta (7.7) | 0.36% | — | Salesmanago LeadooAI | 26/6/2026 | 26/6/2026 | The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal permissions, such as subscribers, to perform SQL… | |
| Aplazada | Alta (8.5) | 0.36% | — | SalesmanagoAILeadooAI | 25/6/2026 | 25/6/2026 | Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Salesforce IntegrationAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions. | |
| Aplazada | Alta (7.2) | 0.51% | — | Freshsales Contact Form 7 IntegrationAI | 6/6/2026 | 23/7/2026 | The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.5) | 0.31% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Baja (2) | 0.25% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of the component Supplier Creation Interface. This manipulation of the argument Address/Company Name causes csv injection. Remote exploitation… | |
| Aplazada | Baja (2) | 0.20% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The manipulation of the argument generic_name results in cross site scripting. The attack may be launched remotely. The… | |
| Aplazada | Baja (2) | 0.20% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of the argument medicine_presentation leads to cross site scripting. The attack may be initiated… | |
| Aplazada | Baja (2) | 0.20% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipulation of the argument company_name can lead to cross site scripting. The attack can be launched remotely. The exploit… | |
| Aplazada | Baja (2) | 0.20% | — | Sourcecodestar Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross site scripting. The attack can be… |