Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
2621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.38% | — | Emxtecnologia Gestao X Business Suite | 4/9/2026 | 17/9/2026 | EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users,… | |
| Aplazada | Alta (7.6) | 0.34% | — | WavesuiteAI | 31/8/2026 | 3/9/2026 | WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser. | |
| Aplazada | Alta (7.5) | 0.60% | — | Bottinelli Informatica Vedo SuiteAI | 19/8/2026 | 9/9/2026 | An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter | |
| Aplazada | Crítica (9.9) | 0.78% | — | Bottinelli Informatica Vedo SuiteAI | 19/8/2026 | 9/9/2026 | SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of… | |
| Analizada | Alta (7.1) | 0.33% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Application Testing Suite executes to compromise Oracle… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks require human… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Application Testing Suite | 18/8/2026 | 27/8/2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized… | |
| Analizada | Alta (7.1) | 0.28% | — | Oracle E-business Suite | 18/8/2026 | 3/9/2026 | Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle E-business Suite | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Call Center Technology.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle E-business Suite | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle E-business Suite | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology.… | |
| Analizada | Alta (8.5) | 0.30% | — | Oracle E-business Suite | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology.… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle E-business Suite | 18/8/2026 | 3/9/2026 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle E-business Suite | 18/8/2026 | 3/9/2026 | Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle U.S. Federal Financials.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle SOA Suite | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle E-business Suite | 18/8/2026 | 30/9/2026 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle E-business Suite | 18/8/2026 | 23/9/2026 | Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet… | |
| Analizada | Media (5.3) | 0.39% | — | Dell Wyse Management Suite | 14/8/2026 | 17/8/2026 | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Alta (7.2) | 0.76% | — | Dell Wyse Management Suite | 14/8/2026 | 18/8/2026 | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution. | |
| Analizada | Alta (7.2) | 0.76% | — | Dell Wyse Management Suite | 14/8/2026 | 17/8/2026 | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution. | |
| Analizada | Media (5.5) | 0.12% | — | Dell Wyse Management Suite | 14/8/2026 | 17/8/2026 | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. |