Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.35% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (8.2) | 0.38% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7) | 0.13% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle… | |
| Analizada | Media (6.3) | 0.17% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle… | |
| Analizada | Media (6.8) | 0.35% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.5) | 0.15% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.1) | 0.45% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.8) | 0.33% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.8) | 0.33% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.1) | 0.45% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9) | 0.39% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.1) | 0.45% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.1) | 0.45% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.1) | 0.45% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Aplazada | Media (5.4) | 0.29% | — | HCL Digital ExperienceAIHCL Digital Experience ComposeAI | 5/8/2026 | 28/8/2026 | The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications using the default login portlet. | |
| Pendiente de análisis | Crítica (10) | 0.81% | — | 3DS 3dexperienceAI3DS Station Launcher APPAI | 28/7/2026 | 30/7/2026 | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution. |