Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
191 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.3) | 0.25% | — | CMP Coming Soon MaintenanceAI | 2/10/2026 | 2/10/2026 | The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Complex Maintenance Repair AND OverhaulAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Complex… | |
| Pendiente de análisis | Alta (8.5) | 0.40% | — | Oracle E-business SuiteAIOracle Complex Maintenance Repair AND OverhaulAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Complex Maintenance Repair AND Overhaul | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Call Center Technology.… | |
| Analizada | Alta (7.1) | 0.29% | — | Oracle Complex Maintenance Repair AND Overhaul | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Aplazada | Media (5.5) | 2.7% | — | Sangfor Operation AND Maintenance Security Management SystemAI | 3/8/2026 | 12/8/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack… | |
| Analizada | Alta (7.5) | 0.28% | — | Oracle Complex Maintenance Repair AND Overhaul | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Complex Maintenance Repair AND Overhaul | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Common Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Complex Maintenance Repair AND Overhaul | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Complex Maintenance Repair AND Overhaul | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Analizada | Alta (8.5) | 0.33% | — | Oracle Complex Maintenance Repair AND Overhaul | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Aplazada | Media (5.5) | 0.72% | — | Acrel Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI | 26/5/2026 | 23/7/2026 | A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of the file /SubstationWEBV2/app/..;/main/upfile. Executing a manipulation of the argument path can lead to path traversal. The attack may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Acrel Eems Enterprise Power Operation AND Maintenance Cloud Platform 3000webv2AI | 26/5/2026 | 23/7/2026 | A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an unknown functionality of the file /SubstationWEBV2/app/..;/calc/getCalcmeterDetailDayListTree. Performing a manipulation of the argument sort results in sql… | |
| Aplazada | Baja (2.1) | 0.38% | — | Acrel Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI | 3/5/2026 | 17/6/2026 | A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.41% | — | Acrel Electrical Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI | 3/5/2026 | 17/6/2026 | A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. The manipulation of the argument fCircuitids leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Peoplesoft Enterprise FIN Maintenance Management | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Peoplesoft Enterprise FIN Maintenance Management | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN… | |
| Aplazada | Alta (8.8) | 0.95% | — | Niteothemes CMP Coming Soon MaintenanceAI | 18/4/2026 | 17/6/2026 | The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. This is due to the function only checking for the `publish_pages` capability… | |
| Aplazada | Alta (7.5) | 0.16% | — | Analytify Under Construction Coming Soon AND Maintenance ModeAI | 7/4/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.This issue affects Under Construction, Coming Soon & Maintenance Mode: from n/a through 2.1.1. | |
| Aplazada | Media (5.3) | 0.30% | — | Seedprod Coming Soon Page Under Construction Maintenance ModeAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <= 6.19.8. | |
| Aplazada | Baja (2.7) | 0.35% | — | Hillstone Networks Operation AND Maintenance Security GatewayAI | 4/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security Gateway on Linux allows Upload a Web Shell to a Web Server.This issue affects Operation and Maintenance Security Gateway: V5.5ST00001B113. | |
| Analizada | Baja (2.1) | 4.9% | — | Sangfor Operation AND Maintenance Security Management System | 26/1/2026 | 17/6/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This impacts the function getInformation of the file /equipment/get_Information of the component HTTP POST Request Handler. Executing a manipulation of the argument fortEquipmentIp can lead to command… | |
| Analizada | Baja (2.1) | 3.1% | — | Sangfor Operation AND Maintenance Security Management System | 26/1/2026 | 17/6/2026 | A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function portValidate of the file /fort/ip_and_port/port_validate of the component HTTP POST Request Handler. Performing a manipulation of the argument port results in command injection. The attack… | |
| Analizada | Media (5.5) | 4.3% | — | Sangfor Operation AND Maintenance Security Management System | 26/1/2026 | 17/6/2026 | A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacted element is an unknown function of the file /fort/audit/get_clip_img of the component HTTP POST Request Handler. Such manipulation of the argument frame/dirno leads to command injection. It is… | |
| Analizada | Media (5.5) | 0.58% | — | Sangfor Operation AND Maintenance Security Management System | 22/1/2026 | 17/6/2026 | A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_mall of the file /fort/login/edit_pwd_mall. The manipulation of the argument flag results in weak password recovery. It is possible to launch the attack remotely. The… |