Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
3237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.36% | — | Eshipper CommerceAI | 20/8/2026 | 20/8/2026 | Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Paymob FOR WoocommerceAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Swatchly - Woocommerce Variation Swatches FOR ProductsAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Yith Woocommerce Membership PremiumAI | 19/8/2026 | 20/8/2026 | Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. | |
| Aplazada | Media (5.3) | 0.32% | — | Wpswings Membership FOR WoocommerceAI | 19/8/2026 | 26/8/2026 | The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Commerce Guided… | |
| Analizada | Media (5.5) | 0.15% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle… | |
| Analizada | Alta (7.2) | 0.27% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.2) | 0.27% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (8.2) | 0.44% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Analizada | Alta (7.5) | 0.35% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Workbench). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Internal operations). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.2) | 0.32% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.5) | 0.34% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (8.2) | 0.32% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… |