Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.34% | — | LeantimeAI | 30/7/2026 | 31/7/2026 | Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redirect authenticated users to arbitrary external sites by manipulating the redirectUrl POST parameter. Attackers can craft a malicious login URL with a tampered redirectUrl value that bypasses… | |
| Aplazada | Alta (7.5) | 0.42% | — | ShiptimeAI | 27/7/2026 | 27/7/2026 | Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions. | |
| Aplazada | Alta (7.1) | 0.41% | — | LeantimeAI | 27/7/2026 | 28/7/2026 | Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer milestone IDs to the tickets.getMilestone JSON-RPC endpoint. Attackers can enumerate integer milestone IDs through the… | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitor Traffic Real Time Statistics PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions. | |
| Pendiente de análisis | Media (6.8) | 0.13% | — | Caliptra Core Runtime FirmwareAI | 22/7/2026 | 22/7/2026 | Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified AXI addresses. The security impact beyond availability is… | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 21/7/2026 | 22/7/2026 | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 21/7/2026 | 22/7/2026 | A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Baja (3.1) | 0.29% | — | Oracle Time AND Labor | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks… | |
| Analizada | Media (5.3) | 0.25% | — | Oracle Time AND Labor | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Time AND Labor | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Time AND Labor | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks… | |
| Analizada | Media (6.7) | 0.43% | — | Oracle Time AND Labor | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Time AND Labor | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks… | |
| Analizada | Baja (3.7) | 0.27% | — | Oracle Time AND Labor | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Time and Labor. Successful… | |
| Analizada | Media (6.6) | 0.27% | — | Oracle Time AND Labor | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Time and Labor. While the… | |
| Analizada | Alta (7.1) | 0.34% | — | Oracle Time AND Labor | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Time AND Labor | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks… | |
| Analizada | Media (6.5) | 0.37% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where… | |
| Analizada | Media (4.3) | 0.37% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.… | |
| Analizada | Media (5.7) | 0.15% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database… | |
| Analizada | Media (4.3) | 0.30% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.… | |
| Analizada | Media (5.6) | 0.13% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database… | |
| Analizada | Media (6.7) | 0.18% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database… | |
| Analizada | Baja (3.8) | 0.15% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database… | |
| Analizada | Media (6.5) | 0.42% | — | Oracle Timesten In-memory Database | 21/7/2026 | 31/7/2026 | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database.… |