Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1095 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.40% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Aplazada | Alta (7) | 0.28% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Aplazada | Media (6.5) | 0.34% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Commerce Guided… | |
| Aplazada | Media (6.5) | 0.33% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Aplazada | Alta (8.2) | 0.43% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Aplazada | Alta (7.1) | 0.21% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the… | |
| Aplazada | Alta (7.7) | 0.34% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (7.3) | 0.30% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 20/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (7.1) | 0.13% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search /… | |
| Aplazada | Alta (7.1) | 0.40% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Aplazada | Alta (7.1) | 0.40% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Aplazada | Alta (8.2) | 0.30% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (7.5) | 0.39% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (8.2) | 0.34% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Media (5.3) | 0.49% | — | Kagisearch SmallwebAI | 13/9/2026 | 15/9/2026 | A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site scripting. The attack is possible to be… | |
| Aplazada | Media (6.9) | 0.83% | — | MogublogAIElasticsearchAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious… | |
| Aplazada | Alta (7.5) | 0.39% | — | WP Fast Total SearchAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions. | |
| Pendiente de análisis | Media (6.3) | 0.54% | — | Opensearch DashboardsAI | 8/9/2026 | 9/9/2026 | Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty… | |
| Aplazada | Media (5.4) | 0.20% | — | Search Atlas SEOAI | 5/9/2026 | 8/9/2026 | The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials. | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Elastic KibanaAICriblAIElasticsearchAI | 3/9/2026 | 8/9/2026 | An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being written beyond the caller's authorized… | |
| Aplazada | Crítica (9.8) | 0.56% | — | JobsearchAI | 3/9/2026 | 7/9/2026 | Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. | |
| Aplazada | Media (5.3) | 0.51% | — | Nousresearch Hermes-agentAIElectronAI | 3/9/2026 | 3/9/2026 | A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of the component Electron Main Process. Performing a manipulation results in allocation of resources. The attack may be initiated remotely.… | |
| Aplazada | Media (5.3) | 0.35% | — | Nousresearch Hermes-agentAI | 3/9/2026 | 5/9/2026 | A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the component Link Title Fetch. Such manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The… | |
| Aplazada | Media (6.9) | 0.50% | — | Nousresearch Hermes-agentAI | 3/9/2026 | 3/9/2026 | A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _sess_nowait of the file s71.py of the component Session Management. This manipulation of the argument session_id causes authorization bypass. The attack can be initiated remotely. The vendor was contacted early about… | |
| Aplazada | Baja (2.1) | 0.47% | — | Nousresearch Hermes-agentAI | 1/9/2026 | 2/9/2026 | A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP Tool. Performing a manipulation results in uncontrolled memory allocation. It is possible to initiate the attack remotely. The exploit has been made… |