Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.40% | — | Sergey Aiwu Ai-copilot-content-generatorAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4. | |
| Analizada | Baja (3.1) | 0.21% | — | Anuaralfetahe Advanced Content Feedback | 10/7/2026 | 6/8/2026 | Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0. | |
| Analizada | Media (6.1) | 0.25% | — | Anuaralfetahe Advanced Content Feedback | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Stored XSS. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpsc-plugin Structured ContentAI | 2/7/2026 | 2/7/2026 | Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Lcweb PrivatecontentAI | 1/7/2026 | 1/7/2026 | Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2. | |
| Aplazada | Media (4.3) | 0.25% | — | Nelio ContentAI | 26/6/2026 | 29/6/2026 | Contributor Broken Access Control in Nelio Content <= 4.3.4 versions. | |
| Analizada | Alta (8.8) | 0.49% | — | Zcontent ZAP Calendar Lite | 19/6/2026 | 21/8/2026 | Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with crafted SQL payloads to extract sensitive… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Content | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Alta (8.7) | 0.33% | — | Oracle Webcenter Content | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks… | |
| Analizada | Alta (8.2) | 0.32% | — | Oracle Webcenter Content | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Content. Successful attacks… | |
| Analizada | Crítica (9.3) | 0.38% | — | Oracle Webcenter Content | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks… | |
| Modificada | Alta (8.7) | 0.33% | — | Oracle Webcenter Content | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks… | |
| Analizada | Crítica (9.3) | 0.38% | — | Oracle Webcenter Content | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Webcenter Content | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks… | |
| Analizada | Media (5.3) | 0.34% | — | Oracle Webcenter Content | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks… | |
| Analizada | Crítica (9.6) | 0.42% | — | Oracle Webcenter Content | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks… | |
| Analizada | Alta (8.4) | 0.40% | — | Oracle Webcenter Content | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks… | |
| Analizada | Alta (8) | 0.16% | — | Oracle Webcenter Content | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks… | |
| Analizada | Crítica (9.6) | 0.21% | — | Oracle Webcenter Content | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks… | |
| Analizada | Crítica (9.3) | 0.20% | — | Oracle Webcenter Content | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Webcenter Content | 17/6/2026 | 18/6/2026 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Content | 17/6/2026 | 18/6/2026 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Webcenter Content | 17/6/2026 | 18/6/2026 | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Webcenter Content | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Content | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.… |