Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
590 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.20% | — | Wpusermanager WP User ManagerAI | 5/10/2026 | 6/10/2026 | Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20. | |
| Aplazada | Media (5.3) | 0.22% | — | Wpusermanager WP User ManagerAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions. | |
| Aplazada | Media (4.3) | 0.20% | — | Wpusermanager WP User ManagerAI | 22/9/2026 | 22/9/2026 | The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in versions up to, and including, 2.9.18. The function is registered on the admin_init hook (which fires for every authenticated user that reaches… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle Enterprise Manager FOR Fusion MiddlewareAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Pendiente de análisis | Alta (7.7) | 0.34% | — | Oracle Enterprise ManagerAIOracle DatabaseAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Core). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Oracle… | |
| Pendiente de análisis | Media (6.5) | 0.30% | — | Oracle Enterprise Manager Base PlatformAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Enterprise Manager… | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Daily Expense ManagerAI | 6/9/2026 | 8/9/2026 | A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Enterprise Manager FOR Systems Infrastructure | 18/8/2026 | 11/9/2026 | Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Storage Server Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base… | |
| Analizada | Media (5.6) | 0.13% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise… | |
| Analizada | Alta (8.6) | 0.37% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Config Console). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Enterprise Manager FOR Systems Infrastructure | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Agent). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager for… | |
| Aplazada | Alta (7.1) | 0.29% | — | Wpexperts License Manager FOR WoocommerceAI | 18/8/2026 | 20/8/2026 | Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Form Vibes Database Manager FOR FormsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Enterprise Manager Base Platform | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Enterprise Manager Base Platform | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Enterprise Manager Base Platform | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise… | |
| Analizada | Media (5.9) | 0.33% | — | Oracle Enterprise Manager Base Platform | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Enterprise Manager Base Platform | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Enterprise Manager Base Platform | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Web Services Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise… | |
| Analizada | Baja (3.5) | 0.14% | — | Oracle Enterprise Manager Base Platform | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base… | |
| Analizada | Alta (7) | 0.29% | — | Oracle Enterprise Manager Base Platform | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise… | |
| Analizada | Alta (8.8) | 0.42% | — | Oracle Enterprise Manager Base Platform | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager… |