Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2757▲ 47 respecto a la semana anterior
Críticas / altas1482▲ 372 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
1267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.25% | — | Softnews Media Group Datalife EngineAI | 23/9/2026 | 24/9/2026 | A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulation of the argument story leads to sql injection. The attack can be initiated remotely. The exploit is publicly available… | |
| Aplazada | Media (6.2) | 0.20% | — | ZTE SmartlifeAI | 20/9/2026 | 22/9/2026 | The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it. | |
| Aplazada | Media (4.3) | 0.33% | — | Smartlife APPAI | 20/9/2026 | 22/9/2026 | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered… | |
| Aplazada | Alta (8.8) | 0.52% | — | Smartlife APPAI | 20/9/2026 | 22/9/2026 | SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered… | |
| Aplazada | Media (5.4) | 0.36% | — | Smartlife APPAI | 20/9/2026 | 22/9/2026 | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Contract Lifecycle Management FOR Public SectorAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: ECC For Award and IDV). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle Contract Lifecycle Management FOR Public SectorAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award/PO). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract… | |
| Aplazada | Alta (7.5) | 0.32% | — | Oracle Product Lifecycle AnalyticsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.… | |
| Aplazada | Alta (7.5) | 0.32% | — | Oracle Product Lifecycle AnalyticsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle Product Lifecycle AnalyticsAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks… | |
| Aplazada | Alta (7.3) | 0.14% | — | Oracle Siebel Apps Life SciencesAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: Life Sciences). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel Apps - Life Sciences executes to compromise Siebel… | |
| Analizada | Alta (8.2) | 0.44% | — | Oracle Agile Product Lifecycle Management | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Agile Product Lifecycle Management | 15/9/2026 | 23/9/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Agile Product Lifecycle Management | 15/9/2026 | 23/9/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: SDK). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. While the vulnerability is in Oracle Agile PLM, attacks… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Agile Product Lifecycle Management | 15/9/2026 | 23/9/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. While the vulnerability is in Oracle Agile… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Agile Product Lifecycle Management | 15/9/2026 | 23/9/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Agile Product Lifecycle Management | 15/9/2026 | 23/9/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Web Client). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from… | |
| Analizada | Media (6.8) | 0.30% | — | Oracle Agile Product Lifecycle Management | 15/9/2026 | 23/9/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM… | |
| Pendiente de análisis | Media (6.1) | 0.24% | — | Oracle Contract Lifecycle Management FOR Public SectorAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Wage Determination Online). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Oracle E-business SuiteAIOracle Contract Lifecycle Management FOR Public SectorAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award/PO). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract… | |
| Aplazada | Alta (8.4) | 0.14% | — | Oracle Product Lifecycle AnalyticsAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to… | |
| Aplazada | Alta (8.1) | 0.36% | — | Oracle Siebel Apps Life SciencesAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: eDetailing). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Life Sciences. Successful attacks require… | |
| Pendiente de análisis | Media (6.2) | 0.54% | — | Volsync Addon-controllerAIRedhat Openshift Lifecycle ManagerAI | 19/8/2026 | 8/9/2026 | A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper escaping of annotation values when they are rendered into YAML. Successful… | |
| Analizada | Alta (8.8) | 0.16% | — | Oracle Product Lifecycle Analytics | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to… | |
| Analizada | Alta (8.7) | 0.41% | — | Oracle Product Lifecycle Analytics | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics.… |