Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Depot RepairAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of… | |
| Aplazada | Alta (7.2) | 0.46% | — | Oracle E-business SuiteAIOracle Depot RepairAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of… | |
| Pendiente de análisis | Media (6.5) | 0.39% | — | Oracle E-business SuiteAIOracle Depot RepairAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Depot Repair Diagnostics). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks… | |
| Pendiente de análisis | Alta (8.1) | 0.35% | — | Oracle E-business SuiteAIOracle Depot RepairAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful… | |
| Aplazada | Alta (8.4) | 0.21% | — | Docudepot PDF Reader PDF Viewer APPAI | 1/4/2026 | 17/6/2026 | An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Aplazada | Alta (8.1) | 0.59% | — | Mikado-themes DepotAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Depot depot allows PHP Local File Inclusion.This issue affects Depot: from n/a through <= 1.16. | |
| Aplazada | Media (4.3) | 0.39% | — | Ship Depot Shipdepot FOR WoocommerceAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Ship Depot ShipDepot for WooCommerce ship-depot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShipDepot for WooCommerce: from n/a through <= 1.2.19. | |
| Modificada | Crítica (9.8) | 0.53% | — | Buynowdepot Advanced Online Ordering AND Delivery Platform | 28/10/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wdesco Advanced Online Ordering and Delivery Platform advanced-online-ordering-and-delivery-platform allows PHP Local File Inclusion.This issue affects Advanced Online Ordering and Delivery… | |
| Modificada | Alta (8.1) | 1.0% | — | Oracle Depot Repair | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: LOVs). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of this vulnerability… | |
| Modificada | Media (6.1) | 1.0% | — | Reddoxx Maildepot | 18/11/2020 | 17/6/2026 | REDDOXX MailDepot 2033 (aka 2.3.3022) allows XSS via an incoming HTML e-mail message. | |
| Modificada | Alta (8.8) | 1.7% | — | Reddoxx Maildepot | 6/10/2020 | 17/6/2026 | REDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users. | |
| Modificada | Alta (7.4) | 1.2% | — | Reddoxx Maildepot | 2/10/2020 | 17/6/2026 | REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout. | |
| Modificada | Crítica (9.8) | 1.2% | — | Zkteco Zkbiosecurity ServerZkteco Facedepot 7B Firmware | 14/8/2020 | 17/6/2026 | A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database. | |
| Modificada | Media (5.9) | 0.74% | — | Zkteco Zkbiosecurity ServerZkteco Facedepot 7B Firmware | 14/8/2020 | 17/6/2026 | Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server. | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Depot Repair | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Depot Repair | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Depot Repair | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Depot Repair | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Depot Repair | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Depot Repair | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Depot Repair | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Depot Repair | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Depot Repair | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful… | |
| Modificada | Media (6.1) | 0.95% | — | Ithemes Builder Theme Depot | 28/8/2019 | 17/6/2026 | iThemes Builder Theme Depot before 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |
| Modificada | Media (5.1) | 1.5% | — | Blaine Lang Filedepot | 27/6/2012 | 16/6/2026 | The filedepot module 6.x-1.x before 6.x-1.3 for Drupal, when accessed using multiple different browsers from the same IP address, causes Internet Explorer sessions to "switch users" when uploading a file, which has unspecified impact possibly involving file uploads to the wrong user directory, aka "Session Management… |