Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

21.073 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.40%—Easyappointments Easy AppointmentsAI24/7/202624/7/2026
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with…
AnalizadaCrítica (9.8)0.86%—Microsoft Azure APP Service FOR Linux24/7/20266/8/2026
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Pendiente de análisisAlta (8.7)0.49%—Johnsoncontrols VictorAIJohnsoncontrols Ccure 9000AIJohnsoncontrols Victor Application ServerAI23/7/20266/8/2026
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.
Pendiente de análisisAlta (7.2)0.39%—Johnsoncontrols Ccure 9000AIJohnsoncontrols Victor Application ServerAI23/7/202630/7/2026
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
AnalizadaMedia (5.3)0.29%—Apple Swiftnio Http/223/7/20261/9/2026
SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.
AnalizadaAlta (7.5)0.43%—Apple Swift-crypto23/7/20264/9/2026
When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This…
AnalizadaAlta (7.7)0.11%—Apple Swiftnio SSL23/7/20264/9/2026
NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is…
AplazadaMedia (6.5)0.22%—Dwbooster Appointment Hour BookingAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
AplazadaMedia (6.5)0.33%💥 PoCEasyappointments Easy AppointmentsAI23/7/202623/7/2026
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
AnalizadaAlta (8.7)0.53%—Netapp Ontap22/7/202620/8/2026
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
Pendiente de análisisAlta (8.4)0.17%—Veeam Software ApplianceAI22/7/202623/7/2026
A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.
AplazadaCrítica (9.2)0.60%—Verba RAG ApplicationAI21/7/202623/7/2026
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the…
AnalizadaCrítica (9.1)0.49%—Oracle Applications Framework21/7/20266/8/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the…
AnalizadaAlta (8.8)0.43%—Oracle Applications Framework21/7/20266/8/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.…
AnalizadaMedia (6.3)0.27%—Oracle Common Applications Calendar21/7/202619/8/2026
Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common…
AnalizadaAlta (7.5)0.15%—Oracle Communications Converged Application Server21/7/202619/8/2026
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: RTP Proxy). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Converged…
AnalizadaAlta (8.1)0.39%—Oracle Communications Converged Application Server21/7/202619/8/2026
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications…
AnalizadaAlta (8)0.38%—Oracle Communications Converged Application Server21/7/20266/8/2026
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with network access via TLS to compromise Oracle Communications Converged…
AnalizadaCrítica (9)0.39%—Oracle Communications Converged Application Server21/7/20266/8/2026
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications…
AnalizadaAlta (7.5)0.44%—Oracle Application Object Library21/7/20265/8/2026
Vulnerabilidad en el producto Oracle Application Object Library de Oracle E-Business Suite (componente: Core). Las versiones compatibles afectadas son 12.2.3-12.2.15. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso a la red a través de HTTP comprometer Oracle Application Object…
AnalizadaAlta (7.5)0.33%—Oracle Application Object Library21/7/20261/8/2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library.…
AnalizadaAlta (7.4)0.34%—Oracle Application Object Library21/7/20261/8/2026
Vulnerabilidad en el producto Oracle Application Object Library de Oracle E-Business Suite (componente: Core). Las versiones compatibles afectadas son 12.2.3-12.2.15. Una vulnerabilidad difícil de explotar permite a un atacante no autenticado con acceso a la red a través de HTTP comprometer Oracle Application Object…
AnalizadaMedia (6.5)0.15%—Oracle Application Object Library21/7/20265/8/2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to…
AnalizadaAlta (8.8)0.43%—Oracle Applications DBA21/7/20261/8/2026
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this…
AnalizadaAlta (7.2)0.49%—Oracle Applications DBA21/7/20261/8/2026
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful…