Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
506 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.13% | — | Oracle Jdeveloper | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to… | |
| Analizada | Alta (7.5) | 0.28% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. While… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful… | |
| Analizada | Baja (3.7) | 0.27% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.… | |
| Analizada | Baja (3.1) | 0.22% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of… | |
| Analizada | Baja (3.7) | 0.27% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of… | |
| Analizada | Media (4.8) | 0.22% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of… | |
| Analizada | Media (6.5) | 0.17% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle… | |
| Analizada | Media (5.9) | 0.32% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful… | |
| Analizada | Media (5.9) | 0.33% | — | Oracle Jdeveloper | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Jdeveloper | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful… | |
| Aplazada | Media (6.4) | 0.42% | — | Wpdeveloper Essential Addons FOR ElementorAI | 21/7/2026 | 23/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.35% | — | Wpdeveloper Essential Addons FOR ElementorAI | 21/7/2026 | 22/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.27% | — | Wpdeveloper BetterdocsAI | 16/7/2026 | 16/7/2026 | The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who… | |
| Aplazada | Media (6.5) | 0.35% | — | Wpdeveloper Better PaymentAI | 13/7/2026 | 13/7/2026 | Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More better-payment allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Better Payment – Instant Payments, Donations,… | |
| Aplazada | Alta (8.8) | 0.67% | — | Wpdeveloper Essential Addons FOR ElementorAI | 11/7/2026 | 15/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct… | |
| Analizada | Baja (3.3) | 0.21% | — | Rfay Examples FOR Developers | 10/7/2026 | 6/8/2026 | Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6. | |
| Aplazada | Media (6.5) | 0.41% | — | Wpdeveloper BetterdocsAI | 10/7/2026 | 10/7/2026 | The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the 'lang' parameter in all versions up to, and including, 4.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Media (6.4) | 0.32% | — | Wpdeveloper Essential Addons FOR ElementorAI | 8/7/2026 | 8/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on event titles sourced from The Events… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpdeveloper ReviewxAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Wpdeveloper Essential BlocksAI | 25/6/2026 | 25/6/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Baja (2.1) | 0.40% | — | Zhilink ADP Application Developer PlatformAI | 21/6/2026 | 22/6/2026 | A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerability affects unknown code of the file /adpweb/a/base/barcodeDetail/import of the component XML Parser. This manipulation causes xml external entity reference. It is possible to initiate the attack… | |
| Aplazada | Baja (2.1) | 0.41% | — | Zhilink ADP Application Developer PlatformAI | 21/6/2026 | 22/6/2026 | A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part of the component testConnection Endpoint. The manipulation of the argument jdbcUrl results in deserialization. The attack may be performed from remote. The exploit has been made public and… | |
| Aplazada | Media (6.4) | 0.35% | — | Wpdeveloper BetterdocsAI | 19/6/2026 | 22/6/2026 | The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs/category-slate-layout Gutenberg block in versions up to, and including, 4.5.3. This is due to insufficient input sanitization… | |
| Aplazada | Alta (7.5) | 0.39% | — | Wpdeveloper EmbedpressAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions. |