Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
21.073 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.40% | — | Easyappointments Easy AppointmentsAI | 24/7/2026 | 24/7/2026 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.8) | 0.86% | — | Microsoft Azure APP Service FOR Linux | 24/7/2026 | 6/8/2026 | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (8.7) | 0.49% | — | Johnsoncontrols VictorAIJohnsoncontrols Ccure 9000AIJohnsoncontrols Victor Application ServerAI | 23/7/2026 | 6/8/2026 | Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1. | |
| Pendiente de análisis | Alta (7.2) | 0.39% | — | Johnsoncontrols Ccure 9000AIJohnsoncontrols Victor Application ServerAI | 23/7/2026 | 30/7/2026 | Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0. | |
| Analizada | Media (5.3) | 0.29% | — | Apple Swiftnio Http/2 | 23/7/2026 | 1/9/2026 | SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0. | |
| Analizada | Alta (7.5) | 0.43% | — | Apple Swift-crypto | 23/7/2026 | 4/9/2026 | When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This… | |
| Analizada | Alta (7.7) | 0.11% | — | Apple Swiftnio SSL | 23/7/2026 | 4/9/2026 | NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is… | |
| Aplazada | Media (6.5) | 0.22% | — | Dwbooster Appointment Hour BookingAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. | |
| Aplazada | Media (6.5) | 0.33% | 💥 PoC | Easyappointments Easy AppointmentsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions. | |
| Analizada | Alta (8.7) | 0.53% | — | Netapp Ontap | 22/7/2026 | 20/8/2026 | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA. | |
| Pendiente de análisis | Alta (8.4) | 0.17% | — | Veeam Software ApplianceAI | 22/7/2026 | 23/7/2026 | A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system. | |
| Aplazada | Crítica (9.2) | 0.60% | — | Verba RAG ApplicationAI | 21/7/2026 | 23/7/2026 | Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Applications Framework | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Applications Framework | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Media (6.3) | 0.27% | — | Oracle Common Applications Calendar | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common… | |
| Analizada | Alta (7.5) | 0.15% | — | Oracle Communications Converged Application Server | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: RTP Proxy). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Converged… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Communications Converged Application Server | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications… | |
| Analizada | Alta (8) | 0.38% | — | Oracle Communications Converged Application Server | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with network access via TLS to compromise Oracle Communications Converged… | |
| Analizada | Crítica (9) | 0.39% | — | Oracle Communications Converged Application Server | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications… | |
| Analizada | Alta (7.5) | 0.44% | — | Oracle Application Object Library | 21/7/2026 | 5/8/2026 | Vulnerabilidad en el producto Oracle Application Object Library de Oracle E-Business Suite (componente: Core). Las versiones compatibles afectadas son 12.2.3-12.2.15. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso a la red a través de HTTP comprometer Oracle Application Object… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Application Object Library | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library.… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Application Object Library | 21/7/2026 | 1/8/2026 | Vulnerabilidad en el producto Oracle Application Object Library de Oracle E-Business Suite (componente: Core). Las versiones compatibles afectadas son 12.2.3-12.2.15. Una vulnerabilidad difícil de explotar permite a un atacante no autenticado con acceso a la red a través de HTTP comprometer Oracle Application Object… | |
| Analizada | Media (6.5) | 0.15% | — | Oracle Application Object Library | 21/7/2026 | 5/8/2026 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Applications DBA | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Applications DBA | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful… |