Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8) | 0.29% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Alta (7.6) | 0.34% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Enterprise Command Center Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.… | |
| Analizada | Media (6.3) | 0.14% | — | Oracle Autonomous Health Framework | 21/7/2026 | 6/8/2026 | Vulnerability in Oracle Autonomous Health Framework (component: Developer triaging platform). Supported versions that are affected are 26.0.0, 26.1.0 and 26.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to… | |
| Aplazada | Alta (8.8) | 0.42% | — | Redux FrameworkAI | 16/7/2026 | 16/7/2026 | The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the… | |
| Aplazada | Crítica (9) | 0.64% | — | DataeaseAIAmazon Redshift DriverAISpringframework Spring FrameworkAI | 15/7/2026 | 16/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting socketFactory=org.springframework.context.support.FileSystemXmlApplicationContext so… | |
| Analizada | Media (6.5) | 0.74% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.46% | — | Microsoft .net FrameworkMicrosoft .net | 14/7/2026 | 24/7/2026 | Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 4.0% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.8) | 4.0% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Crítica (9.8) | 0.29% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+2 | 14/7/2026 | 24/7/2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 14/7/2026 | 24/7/2026 | Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 14/7/2026 | 24/7/2026 | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+4 | 14/7/2026 | 24/7/2026 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+4 | 14/7/2026 | 24/7/2026 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft Azure Active Directory | 14/7/2026 | 24/7/2026 | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.7% | — | Microsoft .net FrameworkMicrosoft Azure Active Directory | 14/7/2026 | 24/7/2026 | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. | |
| Aplazada | Media (5.1) | 0.57% | — | Phoenixframework Phoenix Live ViewAI | 13/7/2026 | 13/7/2026 | Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validation and execute JavaScript in a victim's browser session. The Phoenix.LiveView.Utils.valid_destination!/2 and Phoenix.LiveView.Utils.valid_live_navigation_destination!/2 functions in… | |
| Aplazada | Alta (7.5) | 0.51% | — | Uxper Golo FrameworkAI | 13/7/2026 | 13/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a through <= 1.7.3. | |
| Aplazada | Media (6.4) | 0.26% | — | Tinywebgallery Advanced IframeAI | 8/7/2026 | 8/7/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… |