Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.25% | — | Omnisend Newsletters Email Marketing SMS AND PopupsAI | 30/9/2026 | 30/9/2026 | Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle MarketingAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability… | |
| Pendiente de análisis | Alta (7.7) | 0.34% | — | Oracle MarketingAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. While the vulnerability is in Oracle… | |
| Aplazada | Alta (7.2) | 0.46% | — | Oracle E-business SuiteAIOracle MarketingAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability… | |
| Pendiente de análisis | Alta (7.2) | 0.46% | — | Oracle Siebel Apps - MarketingAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Aplazada | Media (6.5) | 0.45% | — | E-goi Smart Marketing SMS AND Newsletters FormsAI | 12/9/2026 | 14/9/2026 | The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.26% | — | IBM Marketing PlatformAI | 11/9/2026 | 22/9/2026 | A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Smart Marketing SMS AND Newsletters FormsAI | 31/8/2026 | 2/9/2026 | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Marketing Encyclopedia System | 18/8/2026 | 2/9/2026 | Vulnerability in the Oracle Marketing Encyclopedia System product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Marketing | 18/8/2026 | 3/9/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. While the vulnerability is in Oracle… | |
| Analizada | Alta (7.5) | 0.13% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Siebel Apps - Marketing executes to compromise Siebel Apps… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.38% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Alta (7.5) | 0.18% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Alta (7.1) | 0.38% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Siebel Apps - Marketing | 18/8/2026 | 26/8/2026 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this… | |
| Pendiente de análisis | Alta (7.5) | 0.49% | — | Python-socketioAI | 11/8/2026 | 10/9/2026 | python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to version 5.16.4, an… | |
| Aplazada | Media (6.4) | 0.35% | — | Sendpulse Email Marketing NewsletterAI | 1/8/2026 | 12/8/2026 | The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (6.5) | 0.36% | — | Universe Software Computer Marketing Trade AND Industry INC Online Registration AND Workflow Management SystemAI | 22/7/2026 | 5/8/2026 | Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online Registration and Workflow Management System: through 12022026. | |
| Analizada | Media (6.3) | 0.26% | — | Oracle Marketing | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability… | |
| Aplazada | Media (6.1) | 0.36% | — | Fuint Member Marketing SystemAI | 20/7/2026 | 21/7/2026 | Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageController.java file | |
| Aplazada | Media (4.3) | 0.26% | — | Hubspot ALL IN ONE MarketingAI | 17/7/2026 | 17/7/2026 | The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (5.3) | 0.26% | — | Perfect Support Ticketing & Document Management SystemAI | 16/7/2026 | 16/7/2026 | Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization checks. Attackers can add or remove any user,… |