Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2861▲ 226 respecto a la semana anterior
Críticas / altas1331▼ 99 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
21.079 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.28% | — | Appointment Booking CalendarAI | 18/6/2026 | 18/6/2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable via the… | |
| Analizada | Media (4.3) | 0.20% | — | Cisco Webex WEB APP | 17/6/2026 | 22/6/2026 | A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to improper input validation… | |
| Analizada | Media (6) | 0.10% | — | Cisco Umbrella Virtual Appliance | 17/6/2026 | 22/6/2026 | A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Thrivethemes Thrive ApprenticeAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions. | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Applications Manager | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Manager. While… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Siebel Apps - Marketing | 17/6/2026 | 18/6/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Siebel Apps - Marketing | 17/6/2026 | 18/6/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Siebel Apps - Marketing | 17/6/2026 | 18/6/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Siebel Apps - Marketing | 17/6/2026 | 18/6/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Siebel Apps - Marketing | 17/6/2026 | 18/6/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Crítica (9.1) | 0.45% | 💥 PoC | Oracle Application Performance Management | 17/6/2026 | 18/6/2026 | Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise APM - Application… | |
| Analizada | Media (4.7) | 0.14% | — | Oracle Application Development Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle… | |
| Analizada | Media (4.1) | 0.14% | — | Oracle Application Development Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Application Development Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Application Development Framework | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise… | |
| Aplazada | Crítica (9.8) | 0.56% | — | HappyformsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. | |
| Aplazada | Alta (8.2) | 0.34% | — | Hippoo Mobile APP FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Bootstrapped Visual Link PreviewAI | 15/6/2026 | 17/6/2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Simply Schedule AppointmentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Easyappointments Easy AppointmentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Simply Schedule AppointmentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions. | |
| Aplazada | Media (6.3) | 0.25% | — | Ljapps WP Google Review SliderAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Simply Schedule AppointmentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions. | |
| Pendiente de análisis | Media (5.3) | 0.15% | — | Gstreamer PcapparseAI | 15/6/2026 | 17/6/2026 | Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into… | |
| Aplazada | Media (5.1) | 0.24% | — | Appointment Booking CalendarAI | 15/6/2026 | 17/6/2026 | WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify calendar settings and inject persistent cross-site scripting payloads through the admin.php page parameters. Attackers can inject malicious JavaScript into the 'ict' and… |