Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2844▲ 206 respecto a la semana anterior
Críticas / altas1323▼ 110 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
21.646 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.39% | — | Oracle Unified Directory | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Unified Directory | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Unified Directory | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Analizada | Crítica (10) | 0.51% | — | Oracle Unified Directory | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Unified Directory | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Unified Directory. While the… | |
| Analizada | Alta (7.3) | 0.15% | — | Oracle Communications Pricing Design Center | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the… | |
| Pendiente de análisis | Alta (8) | 0.40% | — | Kubeflow Community DistributionAIKubeflow PlatformAI | 21/7/2026 | 23/7/2026 | Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from any user of the Kubeflow UI or APIs,… | |
| Analizada | Media (5.5) | 0.16% | — | Tanium Connect | 21/7/2026 | 18/8/2026 | Tanium addressed an information disclosure vulnerability in Connect. | |
| Analizada | Baja (2.7) | 0.30% | — | Tanium Server | 21/7/2026 | 18/8/2026 | Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server. | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | Canonical Snap-confineAI | 21/7/2026 | 22/7/2026 | A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than… | |
| Aplazada | Alta (8.7) | 0.58% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 22/7/2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured option in ListSelect or ListRadio fields.… | |
| Aplazada | Media (6.9) | 0.49% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 23/7/2026 | Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a… | |
| Aplazada | Alta (7.1) | 0.44% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 23/7/2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding… | |
| Aplazada | Alta (8.4) | 0.44% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 21/7/2026 | Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers… | |
| Aplazada | Crítica (9.3) | 0.54% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 21/7/2026 | Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the… | |
| Pendiente de análisis | Alta (8.4) | 0.18% | — | Canonical SnapdAI | 21/7/2026 | 22/7/2026 | A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution… | |
| Pendiente de análisis | Media (5.6) | 0.13% | — | Canonical SnapdAISystemd-userdbdAI | 21/7/2026 | 22/7/2026 | An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged… | |
| Aplazada | Media (4.3) | 0.41% | — | Uni-yaz FlexcityAI | 21/7/2026 | 28/7/2026 | Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Excessive Allocation. This issue affects FlexCity: from 5.536.0 before 5.542.0. | |
| Aplazada | Media (6.1) | 0.24% | — | Uni-yaz FlexcityAI | 21/7/2026 | 28/7/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue affects FlexCity: from 5.536.0 before 5.542.0. | |
| Aplazada | Media (6.5) | 0.34% | — | Uni-yaz FlexcityAI | 21/7/2026 | 28/7/2026 | Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 before 5.542.0. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Turkmesh Communication Services INC Turkhotspot 5651 LoglamaAI | 21/7/2026 | 21/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This issue affects Turkhotspot 5651 Loglama: from 5.1.2 before 5.1.3. | |
| Analizada | Alta (8.7) | 0.37% | — | Vsee ClinicVsee Clinic API | 20/7/2026 | 14/8/2026 | VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the application server. | |
| Analizada | Crítica (9) | 0.39% | — | Vsee ClinicVsee Clinic API | 20/7/2026 | 14/8/2026 | VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials.… | |
| Aplazada | Media (5.3) | 0.49% | — | Pallets Community Flask Security TOOAI | 20/7/2026 | 23/7/2026 | Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentication flow can mark a session as fresh after verifying an OAuth account that belongs to a different user. If an attacker can operate an already-authenticated but stale victim session, they can… | |
| Aplazada | Media (4.3) | 0.28% | — | Gobito Informatics Technologies Corporate Training Management SystemAI | 20/7/2026 | 21/7/2026 | Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This issue affects Corporate Training Management System: before dd1a9df64. |