Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.20% | — | Oracle Life Sciences Empirica Signal | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are affected are 9.2.1-9.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences Empirica… | |
| Aplazada | Media (5.3) | 0.26% | — | Kutethemes BiolifeAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in kutethemes Biolife biolife allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Biolife: from n/a through <= 3.2.3. | |
| Aplazada | Alta (7.5) | 0.51% | — | Kutethemes BiolifeAI | 8/4/2026 | 24/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Biolife biolife allows PHP Local File Inclusion.This issue affects Biolife: from n/a through <= 3.2.3. | |
| Aplazada | Media (6.5) | 0.22% | — | Awplife Blog FilterAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.6. | |
| Aplazada | Alta (7.1) | 0.18% | — | Stmcan Naturalife ExtensionsAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows Reflected XSS.This issue affects NaturaLife Extensions: from n/a through <= 2.1. | |
| Aplazada | Alta (8.1) | 0.40% | — | Stmcan Naturalife ExtensionsAI | 25/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows PHP Local File Inclusion.This issue affects NaturaLife Extensions: from n/a through <= 2.1. | |
| Aplazada | Media (5.3) | 0.29% | — | Funlus OY WplifecycleAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Funlus Oy WPLifeCycle free-php-version-info allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLifeCycle: from n/a through <= 3.3.1. | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex Save LifeAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Save Life save-life allows PHP Local File Inclusion.This issue affects Save Life: from n/a through <= 1.2.13. | |
| Aplazada | Alta (8.8) | 0.36% | — | Awplife Slider Responsive SlideshowAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow slider-responsive-slideshow allows Object Injection.This issue affects Slider Responsive Slideshow – Image slider, Gallery slideshow: from n/a through <= 1.5.4. | |
| Aplazada | Alta (8.8) | 0.36% | — | WP Life Image Gallery Lightbox Gallery Responsive Photo Gallery Masonry GalleryAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery new-image-gallery allows Object Injection.This issue affects Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery: from n/a through <= 1.6.0. | |
| Aplazada | Alta (8.1) | 0.53% | — | Axiomthemes PJ Life AND Business CoachingAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes PJ | Life & Business Coaching pj allows PHP Local File Inclusion.This issue affects PJ | Life & Business Coaching: from n/a through <= 3.0.0. | |
| Aplazada | Alta (8.8) | 0.49% | — | WP Life Modal Popup BOXAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in A WP Life Modal Popup Box modal-popup-box allows Object Injection.This issue affects Modal Popup Box: from n/a through <= 1.6.1. | |
| Aplazada | Media (5.3) | 0.22% | — | Kraftplugins Wheel OF LifeAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a through <= 1.2.0. | |
| Aplazada | Media (5.4) | 0.09% | — | Intel Battery Life Diagnostic ToolAI | 10/2/2026 | 17/6/2026 | Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via… | |
| Analizada | Media (5.4) | 0.16% | — | IBM Engineering Lifecycle Management | 3/2/2026 | 17/6/2026 | IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 through 7.1.0 Interim Fix 004 IBM Global Configuration Management is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI… | |
| Aplazada | Media (4.3) | 0.21% | — | Ashan Perera LifepressAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Ashan Perera LifePress lifepress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LifePress: from n/a through <= 2.2.1. | |
| Aplazada | Alta (8.8) | 0.41% | — | Strongholdthemes Tech Life CPTAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in strongholdthemes Tech Life CPT techlife-cpt allows Object Injection.This issue affects Tech Life CPT: from n/a through <= 16.4. | |
| Aplazada | Alta (8.8) | 0.41% | — | Designthemes OnelifeAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes OneLife onelife allows Object Injection.This issue affects OneLife: from n/a through <= 3.9. | |
| Aplazada | Alta (7.1) | 0.26% | — | Themegoods DotlifeAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods DotLife dotlife allows Reflected XSS.This issue affects DotLife: from n/a through < 4.9.5. | |
| Analizada | Media (6.5) | 0.21% | — | Oracle Life Sciences Central Coding | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Central Coding product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central… | |
| Analizada | Media (5.3) | 0.25% | — | Oracle Life Sciences Central Designer | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central… | |
| Analizada | Media (6.5) | 0.29% | — | Oracle Life Sciences Central Designer | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences Central… | |
| Analizada | Crítica (9.8) | 0.48% | — | Oracle Agile Product Lifecycle Management FOR Process | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product… | |
| Analizada | Media (6.8) | 0.33% | — | Oracle Agile Product Lifecycle Management FOR Process | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile… | |
| Analizada | Media (6.5) | 0.26% | — | Oracle Life Sciences Central Designer | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central… |