Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1339 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8)0.29%—Oracle Enterprise Command Center Framework21/7/202630/7/2026
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the…
AnalizadaAlta (7.6)0.34%—Oracle Enterprise Command Center Framework21/7/202630/7/2026
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.…
AnalizadaAlta (7.1)0.30%—Oracle Enterprise Command Center Framework21/7/202630/7/2026
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.…
AnalizadaAlta (7.2)0.49%—Oracle Enterprise Command Center Framework21/7/202630/7/2026
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.…
AnalizadaMedia (6.3)0.14%—Oracle Autonomous Health Framework21/7/20266/8/2026
Vulnerability in Oracle Autonomous Health Framework (component: Developer triaging platform). Supported versions that are affected are 26.0.0, 26.1.0 and 26.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to…
AplazadaAlta (8.8)0.42%—Redux FrameworkAI16/7/202616/7/2026
The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the…
AplazadaCrítica (9)0.64%—DataeaseAIAmazon Redshift DriverAISpringframework Spring FrameworkAI15/7/202616/7/2026
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting socketFactory=org.springframework.context.support.FileSystemXmlApplicationContext so…
AnalizadaMedia (6.5)0.74%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.46%—Microsoft .net FrameworkMicrosoft .net14/7/202624/7/2026
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)4.0%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 202614/7/202624/7/2026
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.8)4.0%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
AnalizadaCrítica (9.8)0.29%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+214/7/202624/7/2026
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+914/7/202624/7/2026
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+914/7/202624/7/2026
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+414/7/202624/7/2026
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+414/7/202624/7/2026
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft Azure Active Directory14/7/202624/7/2026
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.7%—Microsoft .net FrameworkMicrosoft Azure Active Directory14/7/202624/7/2026
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
AplazadaMedia (5.1)0.57%—Phoenixframework Phoenix Live ViewAI13/7/202613/7/2026
Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validation and execute JavaScript in a victim's browser session. The Phoenix.LiveView.Utils.valid_destination!/2 and Phoenix.LiveView.Utils.valid_live_navigation_destination!/2 functions in…
AplazadaAlta (7.5)0.51%—Uxper Golo FrameworkAI13/7/202613/7/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a through <= 1.7.3.
AplazadaMedia (6.4)0.26%—Tinywebgallery Advanced IframeAI8/7/20268/7/2026
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
Orbitaley — Vulnerabilidades