Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
21.074 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.49% | — | Oracle Applications DBA | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful… | |
| Analizada | Alta (8.7) | 0.33% | — | Oracle Peoplesoft Enterprise CC Common Application Objects | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Analizada | Media (6.3) | 0.26% | — | Oracle Application Object Library | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful… | |
| Analizada | Media (6.7) | 0.18% | — | Oracle Application Object Library | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Object Library… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Applications Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. Advanced]). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications… | |
| Analizada | Crítica (9.6) | 0.36% | — | Oracle Application Object Library | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Application Object Library. While the… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Application Object Library | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library.… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Applications Framework | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Graph / Charting). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Alta (8.4) | 0.19% | — | Oracle Applications Manager | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Applications Manager… | |
| Analizada | Media (5.7) | 0.14% | — | Oracle Applications Technology Stack | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Applications Technology… | |
| Analizada | Media (6.5) | 0.15% | — | Oracle Applications DBA | 21/7/2026 | 5/8/2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Applications DBA executes to… | |
| Analizada | Media (4.6) | 0.21% | — | Oracle Applications Framework | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Applications Framework | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Applications Framework | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Applications Technology Stack | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Peoplesoft Enterprise CC Common Application Objects | 21/7/2026 | 5/8/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Analizada | Media (6.5) | 0.27% | — | Oracle Applications Manager | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Application Object Library | 21/7/2026 | 5/8/2026 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Application Testing Suite | 21/7/2026 | 24/7/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Application Testing Suite | 21/7/2026 | 24/7/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Application Testing Suite | 21/7/2026 | 24/7/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Application Testing Suite | 21/7/2026 | 24/7/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized access… | |
| Pendiente de análisis | Media (5.3) | 0.35% | — | Apple Find MYAI | 21/7/2026 | 5/10/2026 | El servicio de backend de Apple Buscar hasta el 17-12-2025 permite a un atacante en posesión de un PET (Private Endpoint Token) válido enumerar dispositivos y eliminar dispositivos sin conexión de una cuenta de Apple ID sin activar la autenticación de dos factores o la verificación de propiedad. Esto puede resultar en… | |
| Aplazada | Media (6.5) | 0.34% | — | Bitapps BIT FormAI | 21/7/2026 | 21/7/2026 | The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations. | |
| Aplazada | Media (5.9) | 0.40% | — | Bitapps BIT FormAI | 21/7/2026 | 21/7/2026 | The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file. |