Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.36% | — | Oracle Purchasing | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Purchasing | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Purchasing | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Purchasing | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Purchasing | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this… | |
| Analizada | Alta (7.7) | 0.39% | — | Oracle Purchasing | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. While the vulnerability is in… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Purchasing | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Purchasing | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Purchasing | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Purchasing | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Purchasing executes to compromise Oracle… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Purchasing | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Purchasing | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this… | |
| Aplazada | Media (5.4) | 0.23% | — | Logo Software Industry AND Trade E-logo Purchasing PortalAI | 6/8/2026 | 26/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Purchasing Portal allows Stored XSS. This issue affects e-Logo Purchasing Portal: before 1.52. | |
| Analizada | Alta (8.2) | 0.33% | — | Oracle Peoplesoft Enterprise SCM Purchasing | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Peoplesoft Enterprise SCM Purchasing | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful… | |
| Analizada | Media (5.4) | 0.19% | — | Oracle Peoplesoft Supply Chain Management Purchasing | 20/1/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful… | |
| Aplazada | Media (4.3) | 0.24% | — | SAP Manage Purchasing Info RecordsAI | 11/3/2025 | 17/6/2026 | OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application. | |
| Analizada | Media (5.4) | 0.28% | — | Oracle Peoplesoft Enterprise SCM Purchasing | 21/1/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful… | |
| Modificada | Media (5.4) | 0.27% | — | Oracle Purchasing | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Approvals). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks require human… | |
| Analizada | Alta (8.8) | 0.55% | — | Redon Roblox Purchasing HUB | 8/4/2024 | 17/6/2026 | Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capable of being ran by all users, including admin commands. This allows users to receive products for free and delete/create/update products/tags/etc. The only non-affected command is `/products admin… | |
| Modificada | Alta (7.5) | 1.4% | — | Redon Roblox Purchasing HUB | 27/10/2021 | 17/6/2026 | Roblox-Purchasing-Hub is an open source Roblox product purchasing hub. A security risk in versions 1.0.1 and prior allowed people who have someone's API URL to get product files without an API key. This issue is fixed in version 1.0.2. As a workaround, add `@require_apikey` in `BOT/lib/cogs/website.py` under the route… | |
| Modificada | Alta (8.1) | 0.99% | — | Oracle Purchasing | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Endeca). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Purchasing. Successful attacks of this vulnerability can… | |
| Modificada | Media (6.5) | 1.3% | — | Oracle Peoplesoft Enterprise SCM Purchasing | 15/4/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Supplier Change). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful… | |
| Modificada | Media (4.8) | 0.70% | — | Oracle Peoplesoft Enterprise SCM Purchasing | 15/4/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful… | |
| Modificada | Baja (2.4) | 0.88% | — | Oracle Application Development FrameworkOracle JdeveloperOracle Hyperion Financial ManagementOracle Peoplesoft Enterprise SCM Purchasing | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: OAM). Supported versions that are affected are 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle JDeveloper… |