Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2578▼ 368 respecto a la semana anterior
Críticas / altas1326▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.36%—Oracle E-business Suite Secure Enterprise Search21/7/202617/8/2026
Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
AnalizadaMedia (5.4)0.23%—Oracle E-business Suite Secure Enterprise Search21/7/20264/8/2026
Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
AnalizadaCrítica (9.8)0.57%—Ncp-e NCP Secure Entry ClientNcp-e Secure Enterprise Client26/11/202517/6/2026
NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.
ModificadaAlta (8.8)0.77%—Ncp-e Secure Enterprise Client25/12/202317/6/2026
Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.
ModificadaMedia (4.3)0.59%—Ncp-e Secure Enterprise Client9/12/202317/6/2026
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link.
ModificadaMedia (6.5)0.70%—Ncp-e Secure Enterprise Client9/12/202317/6/2026
Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts.
ModificadaMedia (6.5)0.77%—Ncp-e Secure Enterprise Client9/12/202317/6/2026
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creating a symbolic link.
ModificadaAlta (8.1)0.85%—Ncp-e Secure Enterprise Client9/12/202317/6/2026
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link.
ModificadaCrítica (9.1)1.6%—Oracle E-business Suite Secure Enterprise Search21/10/202017/6/2026
Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
ModificadaAlta (7.8)0.53%—Ncp-e Secure Enterprise Client28/7/202017/6/2026
NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.
ModificadaMedia (5.3)2.3%—Oracle E-business Suite Secure Enterprise Search21/7/201617/6/2026
Unspecified vulnerability in the Oracle E-Business Suite Secure Enterprise Search component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality via vectors related to Search Integration Engine.
ModificadaMedia (6.9)0.35%—Ncp-e Secure ClientNcp-e Secure Enterprise ClientNcp-e Secure Entry Client6/9/201216/6/2026
Multiple untrusted search path vulnerabilities in NCP Secure Enterprise Client before 9.21 Build 68, Secure Entry Client before 9.23 Build 18, and Secure Client - Juniper Edition before 9.23 Build 18 allow local users to gain privileges via a Trojan horse (1) dvccsabase002.dll, (2) conman.dll, (3) kmpapi32.dll, or (4)…
ModificadaMedia (5.5)2.5%—Oracle ApexOracle Application ServerOracle Collaboration SuiteOracle Database Server+518/7/200716/6/2026
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims…
ModificadaAlta (7.5)1.6%—Sygate Technologies EnforcerSygate Technologies Secure Enterprise28/9/200416/6/2026
Sygate Enforcer 3.5MR1 and earlier passes broadcast traffic before authentication, which could allow remote attackers to bypass filtering rules.
ModificadaMedia (5)1.6%—Sygate Technologies Secure Enterprise28/9/200416/6/2026
Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.