Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
2095 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.26% | — | Oracle Advanced Inbound Telephony | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Servers). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony.… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Advanced Benefits | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Affordable Care Act). Supported versions that are affected are 12.2.7-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. Successful… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Advanced Supply Chain Planning | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Supply Chain Planning.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Advanced Collections | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle Advanced Collections product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Collections.… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Advanced Pricing | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful… | |
| Analizada | Alta (7.1) | 0.24% | — | Oracle Advanced Pricing | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.14-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. While the… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Advanced Pricing | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Advanced Pricing | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Advanced Outbound Telephony | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound… | |
| Analizada | Media (6.5) | 0.27% | — | Oracle Advanced Pricing | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful attacks of… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle JD Edwards Enterpriseone Advanced Pricing - Procurement | 21/7/2026 | 6/8/2026 | Vulnerability in the JD Edwards EnterpriseOne Advanced Pricing - Procurement product of Oracle JD Edwards (component: Advanced Pricing). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne… | |
| Analizada | Media (6.3) | 0.26% | — | Oracle Advanced Inbound Telephony | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: SDK client integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound… | |
| Aplazada | Alta (7.5) | 0.51% | — | Themehunk Advance Product SearchAI | 16/7/2026 | 18/7/2026 | The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Surface GO 2 1901 FirmwareMicrosoft Surface GO 2 1926 FirmwareMicrosoft Surface GO 2 1927 FirmwareMicrosoft Surface GO 3 1901 Firmware+23 | 14/7/2026 | 24/7/2026 | Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (6) | 0.27% | — | Siemens Simatic S7-plcsim AdvancedAI | 14/7/2026 | 15/7/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a… | |
| Aplazada | Alta (7.6) | 0.38% | — | Zorem Advanced Shipment Tracking FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through <= 4.0. | |
| Aplazada | Alta (7.5) | 0.35% | — | Phil Kurth Advanced FormsAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through <= 1.9.3.7. | |
| Analizada | Baja (3.1) | 0.21% | — | Anuaralfetahe Advanced Content Feedback | 10/7/2026 | 6/8/2026 | Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0. | |
| Analizada | Media (6.1) | 0.25% | — | Anuaralfetahe Advanced Content Feedback | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Stored XSS. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0. | |
| Aplazada | Media (6.4) | 0.26% | — | Tinywebgallery Advanced IframeAI | 8/7/2026 | 8/7/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Pendiente de análisis | Alta (7.7) | 0.55% | — | Redhat Advanced Cluster Security FOR KubernetesAI | 6/7/2026 | 8/9/2026 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a… | |
| Aplazada | Crítica (9.1) | 1.4% | — | FileorganizerAIFile ManagerAIAdvancedfilemanager Advanced File ManagerAIFilemanagerpro File Manager PROAI | 6/7/2026 | 6/7/2026 | The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing… | |
| Aplazada | Media (6.5) | 0.22% | — | Mosaic Gallery Advanced GalleryAI | 2/7/2026 | 2/7/2026 | Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Advanced Contact Form 7 DBAI | 2/7/2026 | 2/7/2026 | Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions. | |
| Analizada | Alta (7.7) | 0.73% | — | Amazon Advanced Jdbc Wrapper | 1/7/2026 | 9/7/2026 | Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted serialized Java… |