Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
8603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.43% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Enterprise Manager Base… | |
| Analizada | Crítica (9.1) | 0.45% | 💥 PoC | Oracle Application Performance Management | 17/6/2026 | 18/6/2026 | Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise APM - Application… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Oracle Management Service). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise… | |
| Analizada | Crítica (9.6) | 0.47% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Target Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Analizada | Crítica (9.6) | 0.47% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager… | |
| Modificada | Crítica (9.9) | 0.43% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise… | |
| Aplazada | Media (5.3) | 0.39% | — | Abandoned Contact Form 7AI | 16/6/2026 | 17/6/2026 | The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capability check and missing nonce validation in the action__remove_abandoned() function, which is registered to both the wp_ajax_remove_abandoned and… | |
| Aplazada | Crítica (9.8) | 0.56% | 💥 PoC | Integration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | HappyformsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Mailchimp AND Contact Form 7AI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Contact Form 7 HubspotAI | 15/6/2026 | 8/7/2026 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Contact Form 7 AND Constant ContactAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Contact Form 7 Drag AND Drop Multiple File UploadAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Codepeople WP Time Slots Booking FormAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | MW WP FormAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in MW WP Form <= 5.1.3 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | WpformsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Advancedformintegration Advanced Form IntegrationAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions. | |
| Aplazada | Alta (7.1) | 0.25% | 💥 PoC | Codepeople WP Time Slots Booking FormAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions. | |
| Aplazada | Alta (8.6) | 0.64% | — | Contact Form Extender FOR DiviAI | 15/6/2026 | 17/6/2026 | Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field <= 1.0.6 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | 10web Form MakerAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Itpathsolutions Contact Form TO ANY APIAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | CformsiiAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions. |