Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.7) | 0.31% | — | Oracle JD Edwards Enterpriseone Tools | 21/7/2026 | 6/8/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.… | |
| Analizada | Media (5.4) | 0.24% | — | Oracle Peoplesoft Enterprise Peopletools | 21/7/2026 | 27/7/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Media (5.4) | 0.21% | — | Oracle Peoplesoft Enterprise Peopletools | 21/7/2026 | 27/7/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Analizada | Media (4.9) | 0.40% | — | Oracle Peoplesoft Enterprise Peopletools | 21/7/2026 | 27/7/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Media (5.4) | 0.21% | — | Oracle Peoplesoft Enterprise Peopletools | 21/7/2026 | 27/7/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Analizada | Alta (7.4) | 0.37% | — | Oracle Peoplesoft Enterprise Peopletools | 21/7/2026 | 1/8/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Media (5.4) | 0.21% | — | Oracle Peoplesoft Enterprise Peopletools | 21/7/2026 | 27/7/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). The supported version that is affected is 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Analizada | Alta (8.7) | 0.33% | — | Oracle Peoplesoft Enterprise Peopletools | 21/7/2026 | 27/7/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Process Scheduler). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Alta (7.1) | 0.24% | — | Oracle Peoplesoft Enterprise Peopletools | 21/7/2026 | 1/8/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). The supported version that is affected is 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Pendiente de análisis | Media (6.9) | 0.42% | — | Strands Agents ToolsAIElasticsearchAI | 15/7/2026 | 15/7/2026 | Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request forgery (SSRF) issue in the… | |
| Aplazada | Baja (2.1) | 0.46% | — | Apidevtools Json Schema REF ParserAI | 9/7/2026 | 9/7/2026 | A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Pointer.set in the library lib/pointer.ts. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack can be launched remotely. Upgrading to… | |
| Aplazada | Crítica (9.1) | 1.0% | — | Xerte Online ToolsAI | 9/7/2026 | 9/7/2026 | A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control. | |
| Aplazada | Crítica (9.8) | 0.70% | — | Xerte Online ToolsAI | 9/7/2026 | 9/7/2026 | A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed. | |
| Aplazada | Media (5.3) | 0.32% | — | WP Dsgvo ToolsAI | 9/7/2026 | 9/7/2026 | The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email,… | |
| Analizada | Media (6.1) | 0.40% | — | Python Setuptools | 8/7/2026 | 13/7/2026 | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so… | |
| Aplazada | Alta (7.5) | 0.43% | — | Toolset FormsAI | 26/6/2026 | 26/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Wptools Abandoned Cart PROAI | 26/6/2026 | 26/6/2026 | Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | |
| Analizada | Media (6.1) | 0.12% | — | Google Chrome-devtools-mcp | 24/6/2026 | 26/6/2026 | Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforces workspace roots by checking whether path.resolve(filePath) textually falls under one of the configured root paths. path.resolve() does not… | |
| Analizada | Media (6.1) | 0.10% | — | Google Chrome-devtools-mcp | 24/6/2026 | 26/6/2026 | Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.20.0 until 1.1.0, The chrome-devtools-mcp daemon writes its PID file with fs.writeFileSync() to a deterministic runtime path. On typical macOS environments, and on Linux sessions where… | |
| Aplazada | Alta (8.2) | 0.27% | — | Fast ToolsAI | 23/6/2026 | 23/6/2026 | Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting information. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB,… | |
| Aplazada | Media (5.3) | 0.58% | — | WP Dsgvo ToolsAI | 19/6/2026 | 22/6/2026 | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.39. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to supply an arbitrary victim email… | |
| Analizada | Crítica (9.3) | 0.19% | — | Oracle JD Edwards Enterpriseone Tools | 17/6/2026 | 18/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes… | |
| Analizada | Crítica (9.3) | 0.35% | — | Oracle JD Edwards Enterpriseone Tools | 17/6/2026 | 17/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle JD Edwards Enterpriseone Tools | 17/6/2026 | 17/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle JD Edwards Enterpriseone Tools | 17/6/2026 | 18/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards… |