Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2826▼ 248 respecto a la semana anterior
Críticas / altas1321▼ 176 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
21.069 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.35% | — | Oracle Mobile Application Server | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Applications DBA | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: JRI and other Java utils). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications DBA.… | |
| Analizada | Alta (7.1) | 0.38% | — | Oracle Applications DBA | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Peoplesoft Enterprise CC Common Application Objects | 18/8/2026 | 4/9/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise PeopleSoft… | |
| Analizada | Alta (7.5) | 0.13% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Siebel Apps - Marketing executes to compromise Siebel Apps… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.38% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Alta (7.5) | 0.18% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Alta (7.1) | 0.38% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Pendiente de análisis | Alta (7.3) | 0.17% | — | Dell AppsyncAIDell Metro NodeAIDell UCC EdgeAIDell VxrailAI+5 | 18/8/2026 | 20/8/2026 | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4… | |
| Aplazada | Media (6.5) | 0.33% | — | Appointment Booking SystemAI | 18/8/2026 | 20/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | JetappointmentAI | 18/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | |
| Aplazada | Media (6.5) | 0.35% | — | Dwbooster Appointment Hour BookingAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Dynamiapps Frontend AdminAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. | |
| Pendiente de análisis | Media (5.2) | 0.18% | — | Citrix Workspace APPAI | 18/8/2026 | 28/8/2026 | External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607. | |
| Modificada | Media (4.3) | 0.46% | 💥 PoC | Apple SafariApple IpadosApple Iphone OSApple Macos | 17/8/2026 | 14/9/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (6.6) | 0.15% | 💥 PoC | Apple IpadosApple Iphone OSApple Macos | 17/8/2026 | 14/9/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or read kernel memory. | |
| Modificada | Media (6.5) | 0.42% | — | Apple IpadosApple Iphone OSApple Macos | 17/8/2026 | 14/9/2026 | The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service. | |
| Modificada | Alta (8.8) | 0.59% | — | Apple IpadosApple Iphone OSApple Macos | 17/8/2026 | 14/9/2026 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to arbitrary code execution. | |
| Modificada | Alta (7.5) | 0.69% | 💥 PoC | Apple IpadosApple Iphone OSApple Macos | 17/8/2026 | 14/9/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected system termination. | |
| Modificada | Media (5.4) | 0.24% | — | Apple SafariApple IpadosApple Iphone OSApple Macos | 17/8/2026 | 14/9/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Media (4.3) | 0.46% | — | Apple SafariApple IpadosApple Iphone OSApple Macos | 17/8/2026 | 14/9/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash. |