Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
9651 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.26% | — | Oracle E-business Suite | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Partner Dashboard). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Partner Management. Successful… | |
| Analizada | Media (6.3) | 0.26% | — | Oracle E-business Suite | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product of Oracle E-Business Suite (component: Web Service Provider). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business… | |
| Analizada | Media (5.4) | 0.29% | — | Oracle E-business Suite | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SDP Number Portability. Successful… | |
| Analizada | Alta (7.7) | 0.39% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. While the… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle SOA Suite.… | |
| Analizada | Alta (8.2) | 0.44% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Business Process Management Suite | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite.… | |
| Analizada | Crítica (9.6) | 0.36% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. While the… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite.… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle JD Edwards Enterpriseone Requirements Planning | 21/7/2026 | 6/8/2026 | Vulnerability in the JD Edwards EnterpriseOne Requirements Planning product of Oracle JD Edwards (component: Requirements Planning). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle E-business Suite | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Project Costing product of Oracle E-Business Suite (component: Enterprise Command Center). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Project Costing. Successful… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle E-business Suite | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Performance Management. Successful… | |
| Analizada | Alta (8.5) | 0.33% | — | Oracle E-business Suite | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration.… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle E-business Suite | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document Management… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Application Testing Suite | 21/7/2026 | 24/7/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Application Testing Suite | 21/7/2026 | 24/7/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Application Testing Suite | 21/7/2026 | 24/7/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Application Testing Suite | 21/7/2026 | 24/7/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized access… | |
| Aplazada | Media (6.9) | 0.20% | — | RattlerAIRattler Conda TypesAIConda PixiAIConda MambaAI+1 | 21/7/2026 | 23/7/2026 | Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_conda_types` performs only `.trim()` on the `command` field before the linker joins it onto the install prefix and writes an executable Python script. A malicious… | |
| Analizada | Alta (7.3) | 0.20% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host. | |
| Analizada | Media (6) | 0.24% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. | |
| Analizada | Baja (1.8) | 0.25% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory. |