Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Portal | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful… | |
| Analizada | Alta (8.5) | 0.33% | — | Oracle Webcenter Portal | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While… | |
| Analizada | Alta (7.6) | 0.32% | — | Oracle Webcenter Portal | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Webcenter Portal | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability… | |
| Analizada | Alta (8.7) | 0.34% | — | Oracle Webcenter Portal | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Webcenter Portal | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful… | |
| Analizada | Alta (7.1) | 0.32% | — | Oracle Webcenter Portal | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Alta (7.7) | 0.25% | — | Oracle Webcenter Portal | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Portal | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via RMI to compromise Oracle WebCenter Portal. Successful… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Portal | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Portal | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Webcenter Portal | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Aplazada | Crítica (9.8) | 0.82% | — | Lemonldap NG PortalAI | 16/8/2026 | 26/8/2026 | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends. Before redirecting to the identity provider, extractFormInfo() creates the state… | |
| Aplazada | Crítica (9.3) | 0.34% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions… | |
| Aplazada | Crítica (9.3) | 0.41% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |
| Aplazada | Alta (8.6) | 0.39% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |
| Aplazada | Crítica (9.1) | 0.43% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |
| Aplazada | Crítica (9.1) | 0.43% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAI | 13/8/2026 | 28/8/2026 | : Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All… | |
| Aplazada | Media (5.3) | 0.33% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |
| Aplazada | Alta (8.2) | 0.34% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |
| Aplazada | Crítica (10) | 0.50% | — | Soft Solutions Priority ERP Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |
| Aplazada | Alta (8.6) | 0.42% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).. This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions).: All versions without Priwall v3. | |
| Aplazada | Alta (8.5) | 0.36% | — | Wpjobportal WP JOB PortalAI | 6/8/2026 | 12/8/2026 | Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions. | |
| Aplazada | Media (5.4) | 0.23% | — | Logo Software Industry AND Trade E-logo Purchasing PortalAI | 6/8/2026 | 26/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Purchasing Portal allows Stored XSS. This issue affects e-Logo Purchasing Portal: before 1.52. | |
| Aplazada | Alta (8.1) | 0.61% | — | ZportalsAI | 5/8/2026 | 26/8/2026 | The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any authenticated user (Subscriber or higher) to upload arbitrary PHP files and achieve remote code execution. |