Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.1) | 0.27% | — | Calculated Fields FormAI | 3/10/2026 | 3/10/2026 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'arbitrary (whichever names the admin bound via url.<name>)' parameter in all versions up to, and including, 5.5.1.5 due to… | |
| Aplazada | Baja (2.1) | 0.21% | — | Calcom Cal.diyAI | 2/10/2026 | 2/10/2026 | A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (4.7) | 0.20% | — | Calculated Fields FormAI | 1/10/2026 | 3/10/2026 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (attacker-chosen name matching the form's url.<name> predefined value)' parameter in all versions up to, and including, 5.5.1.3 due… | |
| Aplazada | Media (6.1) | 0.21% | — | Calculatedfields Calculated Fields FormAI | 1/10/2026 | 1/10/2026 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (any URL parameter consumed by the form's calculated equation)' parameter in all versions up to, and including, 5.5.1.3 due to… | |
| Aplazada | Alta (7.1) | 0.18% | — | Calculated Fields FormAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions. | |
| Pendiente de análisis | Alta (8.8) | 0.64% | — | Apache Calcite AvaticaAI | 22/9/2026 | 22/9/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avatica. Plugin instantiation (via AvaticaUtils#instantiatePlugin and other methods) initializes arbitrary classes via unrestricted calls to Class.forName(String) which by default triggers initialization.… | |
| Aplazada | Media (5.3) | 0.29% | — | Flexible Quantity Measurement Price CalculatorAI | 11/9/2026 | 11/9/2026 | Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions. | |
| Aplazada | Media (4.8) | 0.28% | — | WgerAIMicrosoft ExcelAILibreoffice CalcAI | 6/9/2026 | 8/9/2026 | wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or execute code when admins open the exported file in Excel or LibreOffice Calc. | |
| Aplazada | Alta (7.1) | 0.25% | — | Calculation FOR Contact Form 7AI | 3/9/2026 | 3/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions. | |
| Modificada | Media (4) | 0.17% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to… | |
| Modificada | Media (4.1) | 0.13% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to… | |
| Modificada | Baja (3.6) | 0.13% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to… | |
| Modificada | Alta (7.1) | 0.18% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to… | |
| Modificada | Alta (7.9) | 0.18% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to… | |
| Modificada | Media (4.3) | 0.27% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful… | |
| Modificada | Baja (3.7) | 0.26% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.… | |
| Modificada | Media (5.3) | 0.30% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful… | |
| Modificada | Alta (7.6) | 0.27% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful… | |
| Modificada | Media (5.9) | 0.25% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.… | |
| Analizada | Alta (7) | 0.29% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.… | |
| Modificada | Baja (3.1) | 0.22% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.… | |
| Modificada | Baja (3.1) | 0.25% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Modificada | Media (5.4) | 0.29% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Modificada | Alta (8) | 0.29% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Modificada | Alta (8.2) | 0.29% | — | Oracle Hyperion Calculation Manager | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SFTP to compromise Oracle Hyperion Calculation Manager. While the… |