Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

1236 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.9)0.39%—Oracle Service Delivery Platform21/7/202628/7/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery…
AnalizadaCrítica (9.8)0.51%—Oracle Service Delivery Platform21/7/202628/7/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery…
AnalizadaCrítica (9.8)0.51%—Oracle Service Delivery Platform21/7/202628/7/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery…
AnalizadaCrítica (9.8)0.51%—Oracle Service Delivery Platform21/7/202628/7/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery…
AplazadaMedia (6.8)0.18%—Gnome EvinceAITUG TEX LiveAI21/7/202623/7/2026
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX…
AplazadaMedia (5.1)0.57%—Phoenixframework Phoenix Live ViewAI13/7/202613/7/2026
Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validation and execute JavaScript in a victim's browser session. The Phoenix.LiveView.Utils.valid_destination!/2 and Phoenix.LiveView.Utils.valid_live_navigation_destination!/2 functions in…
AplazadaMedia (6.5)0.22%—Livemesh Addons FOR Wpbakery Page BuilderAI2/7/20262/7/2026
Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.
AnalizadaAlta (8.8)0.63%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20261/7/2026
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
AnalizadaAlta (8.8)1.0%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/202627/8/2026
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
AnalizadaAlta (8.8)0.50%💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20261/7/2026
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
AnalizadaAlta (8.7)0.56%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20262/7/2026
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
AnalizadaMedia (6.9)0.56%💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20262/7/2026
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
AnalizadaAlta (7.1)0.58%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20262/7/2026
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
AplazadaAlta (7.5)0.42%—Wpfactory Print Invoice AND Delivery Notes FOR WoocommerceAI26/6/202626/6/2026
Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.
AplazadaMedia (4.3)0.27%—Live Copy Paste FOR ElementorAI26/6/20265/10/2026
Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
AplazadaMedia (4.3)0.35%—24liveblogAI24/6/202625/6/2026
The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX function in versions up to, and including, 2.2. The handler only verifies the 'lb24' nonce (which is generated and localized to any user with block…
AplazadaMedia (4.3)0.36%—24liveblogAI24/6/202629/6/2026
The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block_enqueue_scripts() function being hooked to enqueue_block_editor_assets and, for any non-administrator user, falling back to loading the…
AplazadaMedia (6.5)0.34%💥 PoCLaravelAIFilamentphp FilamentAILaravel LivewireAI22/6/202623/6/2026
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the Livewire component the schema is embedded in. However, some schemas, such as…
AplazadaAlta (7.4)0.28%—Chatway Live Chat - AI Chatbot Customer Support FAQ & Helpdesk Customer Service & Chat ButtonsAI15/6/202617/6/2026
Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Customer Service &amp; Chat Buttons <= 1.4.8 versions.
AplazadaAlta (7.5)0.42%—Wpcloud Woocommerce PDF Invoices Packing Slips Delivery Notes AND Shipping LabelsAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions.
AplazadaBaja (3.7)0.42%—OlivetinAI15/6/202624/6/2026
OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/api/api.go does not perform any authentication or authorization checks. Unlike all other data-returning API endpoints, it does not call auth.UserFromApiCall…
AplazadaAlta (7.5)0.54%—OlivetinAI15/6/202624/6/2026
OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, the template engine uses a single shared text/template.Template instance (tpl package-level variable in service/internal/tpl/templates.go) across all goroutines. Every action execution calls tpl.Parse(source)…
AplazadaCrítica (9.3)0.40%—Order Delivery DateAI15/6/202617/6/2026
Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.
AplazadaCrítica (9.8)0.54%—Datalogics Ecommerce DeliveryAI15/6/202617/6/2026
Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.
AplazadaCrítica (9.8)0.56%—Broadcast Live VideoAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.