Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2578▼ 368 respecto a la semana anterior
Críticas / altas1326▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.36% | — | Oracle E-business Suite Secure Enterprise Search | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle E-business Suite Secure Enterprise Search | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (9.8) | 0.57% | — | Ncp-e NCP Secure Entry ClientNcp-e Secure Enterprise Client | 26/11/2025 | 17/6/2026 | NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability. | |
| Modificada | Alta (8.8) | 0.77% | — | Ncp-e Secure Enterprise Client | 25/12/2023 | 17/6/2026 | Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location. | |
| Modificada | Media (4.3) | 0.59% | — | Ncp-e Secure Enterprise Client | 9/12/2023 | 17/6/2026 | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link. | |
| Modificada | Media (6.5) | 0.70% | — | Ncp-e Secure Enterprise Client | 9/12/2023 | 17/6/2026 | Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts. | |
| Modificada | Media (6.5) | 0.77% | — | Ncp-e Secure Enterprise Client | 9/12/2023 | 17/6/2026 | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creating a symbolic link. | |
| Modificada | Alta (8.1) | 0.85% | — | Ncp-e Secure Enterprise Client | 9/12/2023 | 17/6/2026 | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link. | |
| Modificada | Crítica (9.1) | 1.6% | — | Oracle E-business Suite Secure Enterprise Search | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Alta (7.8) | 0.53% | — | Ncp-e Secure Enterprise Client | 28/7/2020 | 17/6/2026 | NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant. | |
| Modificada | Media (5.3) | 2.3% | — | Oracle E-business Suite Secure Enterprise Search | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle E-Business Suite Secure Enterprise Search component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality via vectors related to Search Integration Engine. | |
| Modificada | Media (6.9) | 0.35% | — | Ncp-e Secure ClientNcp-e Secure Enterprise ClientNcp-e Secure Entry Client | 6/9/2012 | 16/6/2026 | Multiple untrusted search path vulnerabilities in NCP Secure Enterprise Client before 9.21 Build 68, Secure Entry Client before 9.23 Build 18, and Secure Client - Juniper Edition before 9.23 Build 18 allow local users to gain privileges via a Trojan horse (1) dvccsabase002.dll, (2) conman.dll, (3) kmpapi32.dll, or (4)… | |
| Modificada | Media (5.5) | 2.5% | — | Oracle ApexOracle Application ServerOracle Collaboration SuiteOracle Database Server+5 | 18/7/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims… | |
| Modificada | Alta (7.5) | 1.6% | — | Sygate Technologies EnforcerSygate Technologies Secure Enterprise | 28/9/2004 | 16/6/2026 | Sygate Enforcer 3.5MR1 and earlier passes broadcast traffic before authentication, which could allow remote attackers to bypass filtering rules. | |
| Modificada | Media (5) | 1.6% | — | Sygate Technologies Secure Enterprise | 28/9/2004 | 16/6/2026 | Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session. |