Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
1098 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.38% | — | Cubewp FrameworkAI | 10/8/2026 | 26/8/2026 | The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft,… | |
| Analizada | Media (5.9) | 0.36% | — | Ash-hq ASH Framework | 9/8/2026 | 18/8/2026 | Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in decode_values/2 in lib/ash/page/keyset.ex, which… | |
| Aplazada | Alta (8.1) | 0.39% | — | Cubewp FrameworkAI | 9/8/2026 | 26/8/2026 | The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks. | |
| Aplazada | Media (6.9) | 0.40% | — | AIL FrameworkAI | 6/8/2026 | 26/8/2026 | AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedded directly into the JavaScript onclick handler used to display a stored screenshot, without context-appropriate encoding. An attacker who can cause a specially crafted URL to be recorded in the… | |
| Aplazada | Alta (8.2) | 0.40% | — | Circl AIL FrameworkAI | 6/8/2026 | 26/8/2026 | AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation, the application returned the error value directly as an HTML response using str(res[0]). If attacker-controlled input was included in the generated error… | |
| Analizada | Media (4.6) | 0.23% | — | Eclipse Accessibility Tools FrameworkSoumu Michecker | 5/8/2026 | 10/8/2026 | In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this vulnerability is exploited, a malicious third party… | |
| Aplazada | Media (6.5) | 0.34% | — | Gdpr Framework BY Data443AI | 4/8/2026 | 26/8/2026 | The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's… | |
| Aplazada | Alta (7.5) | 0.94% | — | Cubewp FrameworkAI | 2/8/2026 | 12/8/2026 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.… | |
| Aplazada | Media (6.5) | 0.47% | — | Cubewp FrameworkAI | 1/8/2026 | 12/8/2026 | The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient input sanitization in the cubewp_remove_relation() AJAX function, specifically the use of wp_unslash() on the relation_id parameter before interpolating it directly into a… | |
| Aplazada | Media (5.2) | 0.24% | — | Tridium Niagara FrameworkAITridium Niagara Enterprise SecurityAI | 23/7/2026 | 23/7/2026 | Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before… | |
| Aplazada | Media (5.3) | 0.29% | — | Civi FrameworkAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Applications Framework | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Applications Framework | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Applications Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. Advanced]). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Applications Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Graph / Charting). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Media (4.6) | 0.21% | — | Oracle Applications Framework | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Applications Framework | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Applications Framework | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Analizada | Alta (8.3) | 0.38% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Alta (8.8) | 0.42% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Alta (8) | 0.29% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Alta (7.6) | 0.34% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.… |