Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
443 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.31% | 💥 PoC | Oracle Financial Services Analytical Applications Infrastructure | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Media (6.5) | 0.37% | — | Oracle Applications DBA | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of… | |
| Analizada | Media (6.1) | 1.1% | — | Zohocorp Manageengine Applications Manager | 18/12/2025 | 30/9/2026 | Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view. | |
| Aplazada | Alta (8.8) | 4.2% | 💥 PoC | Zohocorp Manageengine Applications ManagerAI | 11/11/2025 | 25/9/2026 | Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature. | |
| Aplazada | Alta (8.4) | 0.20% | — | I-O Data Device NAS Management ApplicationsAI | 23/10/2025 | 17/6/2026 | Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege. | |
| Analizada | Alta (7.5) | 0.32% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: System Configuration). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Analizada | Alta (8.1) | 0.33% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via… | |
| Analizada | Media (4.3) | 0.24% | — | Oracle Applications Framework | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Media (6.1) | 0.23% | — | Oracle Applications Manager | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Application Logging Interfaces). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications… | |
| Analizada | Crítica (9.8) | 0.47% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Media (6.5) | 0.33% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via… | |
| Analizada | Media (4.3) | 0.24% | — | Oracle Applications Framework | 21/10/2025 | 30/9/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Media (5.4) | 0.24% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 30/9/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Media (6.5) | 0.96% | — | Zohocorp Manageengine Applications Manager | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor. | |
| Aplazada | Crítica (9.4) | 0.27% | — | Zigbee Ezsp Host ApplicationsAI | 17/10/2025 | 17/6/2026 | Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the buffer overflows, stack corruption is possible. In certain conditions, this could lead to arbitrary code execution. Access to a network key is required to exploit this vulnerability. | |
| Analizada | Media (5.4) | 0.40% | — | Zohocorp Manageengine Applications Manager | 23/7/2025 | 17/6/2026 | Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor. | |
| Analizada | Media (5.3) | 0.29% | — | Oracle Financial Services Analytical Applications Infrastructure | 15/7/2025 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.8, 8.0.8.5, 8.0.8.6, 8.1.1.4 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Analizada | Media (6.4) | 0.27% | — | Oracle Applications Framework | 15/7/2025 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the… | |
| Analizada | Baja (3.6) | 0.15% | — | Oracle Applications Technology Stack | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration). Supported versions that are affected are 12.2.3-12.2.14. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Applications Technology… | |
| Analizada | Media (5.4) | 0.33% | — | Oracle Applications Framework | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Alta (7.5) | 0.67% | — | Oracle Common Applications | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications.… | |
| Analizada | Media (5.4) | 0.36% | — | Oracle Applications Framework | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Alta (7.3) | 0.75% | — | Microsoft SQL Server Management StudioMicrosoft Visual Studio Tools FOR Applications 2019Microsoft Visual Studio Tools FOR Applications 2019 SDKMicrosoft Visual Studio Tools FOR Applications 2022+1 | 12/4/2025 | 17/6/2026 | Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (6.5) | 0.26% | — | Custom Database Applications BY CaspioAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Caspio Bridge Custom Database Applications by Caspio custom-database-applications-by-caspio allows DOM-Based XSS.This issue affects Custom Database Applications by Caspio: from n/a through <= 2.1. |