Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 300 respecto a la semana anterior
Críticas / altas1348▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.27% | — | Oracle Human Capital Management Configuration Workbench | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench.… | |
| Analizada | Alta (7.3) | 0.31% | — | Oracle Human Capital Management Configuration Workbench | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Configuration… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Human Capital Management Configuration Workbench | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HCM Configuration… | |
| Analizada | Media (6.5) | 0.39% | — | Oracle Human Capital Management Configuration Workbench | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HCM Configuration… | |
| Analizada | Media (6.5) | 0.41% | — | Oracle Peoplesoft Enterprise Human Capital Management Absence Management | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Absence… | |
| Analizada | Media (6.5) | 0.39% | — | SAP Human Capital Management | 14/4/2026 | 17/6/2026 | During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact… | |
| Aplazada | Alta (7.7) | 0.78% | — | SAP Capital Yield TAX ManagementAI | 8/4/2025 | 17/6/2026 | SAP Capital Yield Tax Management has directory traversal vulnerability due to insufficient path validation. This could allow an attacker with low privileges to read files from directory which they don�t have access to, hence causing a high impact on confidentiality. Integrity and Availability are not affected. | |
| Modificada | Crítica (9.8) | 1.8% | — | Epicor Human Capital Management | 28/3/2025 | 17/6/2026 | A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this vulnerability by injecting malicious SQL payloads… | |
| Aplazada | Media (6.5) | 0.29% | — | Capitalize MY TitleAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Capitalize My Title Capitalize My Title capitalize-my-title allows Stored XSS.This issue affects Capitalize My Title: from n/a through <= 0.5.3. | |
| Modificada | Media (5.4) | 0.40% | — | Sureswiftcapital Simple Calendar | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Calendar Simple Calendar – Google Calendar Plugin allows Stored XSS.This issue affects Simple Calendar – Google Calendar Plugin: from n/a through 3.2.6. | |
| Modificada | Media (6.1) | 0.41% | — | SAP Human Capital Management | 12/12/2023 | 17/6/2026 | The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the… | |
| Modificada | Media (5.4) | 0.41% | — | Oracle Peoplesoft Enterprise Human Capital Management Human Resources | 18/4/2023 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Administer Workforce). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Modificada | Media (6.5) | 0.83% | — | SAP ERP Human Capital Management | 9/2/2022 | 17/6/2026 | SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor cause availability impacts. | |
| Modificada | Media (5.5) | 0.25% | — | Intel Capital Global Summit | 9/2/2022 | 17/6/2026 | Improper access control in the Intel(R) Capital Global Summit Android application may allow an authenticated user to potentially enable information disclosure via local access. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (4.3) | 0.57% | — | SAP ERP Human Capital Management | 10/11/2021 | 17/6/2026 | SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor cause availability impacts. | |
| Modificada | Crítica (9.1) | 2.2% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Readystart V4+7 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0). The total length of an TCP payload… | |
| Modificada | Crítica (9.1) | 2.2% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+6 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0). Malformed TCP packets with a corrupted SACK option leads to Information Leaks and… | |
| Modificada | Alta (7.5) | 1.2% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Readystart V4+7 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions <… | |
| Modificada | Crítica (9.8) | 1.5% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+19 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions <… | |
| Modificada | Alta (7.5) | 1.5% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+6 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). When processing a DHCP ACK message, the DHCP client application does not validate the length of the Vendor option(s), leading to Denial-of-Service conditions.… | |
| Modificada | Alta (7.5) | 1.5% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+6 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). The DHCP client application does not validate the length of the Domain Name Server IP option(s) (0x06) when processing DHCP ACK packets. This may lead to… | |
| Modificada | Alta (7.5) | 1.5% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+6 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). When processing a DHCP OFFER message, the DHCP client application does not validate the length of the Vendor option(s), leading to Denial-of-Service conditions.… | |
| Modificada | Crítica (9.1) | 2.0% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Readystart V4+7 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0). The total length of an ICMP payload… | |
| Modificada | Crítica (9.1) | 1.6% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+6 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions). The total length of an UDP payload (set in the IP header) is unchecked. This may lead to various side effects, including Information… |