Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.2% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive application data like service bindings within that space. | |
| Modificada | Alta (7.5) | 1.1% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that deliver information about system configuration in SAP HANA Extended Application Services, 1.0. | |
| Modificada | Media (6.5) | 0.85% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication. | |
| Modificada | Alta (7.5) | 1.7% | — | SAP Hana Extended Application Services | 12/12/2017 | 17/6/2026 | Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller service are missing user input validation which could allow unprivileged attackers to forge audit log lines. Hence the interpretation of audit log files could be hindered or… | |
| Modificada | Crítica (9.8) | 5.2% | — | Adobe Flash PlayerAdobe Flash Player Extended Support ReleaseAdobe Flash Player FOR LinuxAdobe AIR+2 | 27/6/2017 | 17/6/2026 | Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0.267, Adobe Flash Player for Microsoft Edge and Internet Explorer 11 before 20.0.0.267, Adobe Flash Player for Internet… | |
| Modificada | Alta (7.8) | 1.4% | — | IPA Empirical Project Monitor - Extended | 22/5/2017 | 17/6/2026 | Untrusted search path vulnerability in Empirical Project Monitor - eXtended all versions allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (6.1) | 1.2% | — | IPA Empirical Project Monitor - Extended | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Empirical Project Monitor - eXtended all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 0.89% | — | IPA Empirical Project Monitor - Extended | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Empirical Project Monitor - eXtended all versions allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.9) | 2.1% | — | Sonicwall Netextender | 26/8/2015 | 17/6/2026 | Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder. | |
| Modificada | Alta (9) | 4.8% | — | Belkin N300 Dual-band Wi-fi Range Extender Firmware | 13/8/2015 | 17/6/2026 | Belkin N300 Dual-Band Wi-Fi Range Extender with firmware before 1.04.10 allows remote authenticated users to execute arbitrary commands via the (1) sub_dir parameter in a formUSBStorage request; pinCode parameter in a (2) formWpsStart or (3) formiNICWpsStart request; (4) wps_enrolee_pin parameter in a formWlanSetupWPS… | |
| Modificada | Media (4.3) | 2.7% | — | Nextendweb Facebook Connect | 24/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the new_fb_sign_button function in nextend-facebook-connect.php in Nextend Facebook Connect plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter. | |
| Modificada | Alta (10) | 2.2% | — | SAP Hana Extended Application Services | 22/1/2015 | 17/6/2026 | The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Nextendweb Nextend Facebook Connect | 5/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fb_login_button parameter in a newfb_update_options action. | |
| Modificada | Media (5.4) | 0.27% | — | Xtendcu Mobile | 19/10/2014 | 17/6/2026 | The XtendCU Mobile (aka com.metova.cuae.xtend) application 1.0.28 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 2.8% | — | SAP Hana Extended Application Services | 31/7/2014 | 17/6/2026 | SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a private IU5 SDK application that was once public. | |
| Modificada | Baja (2.9) | 1.5% | — | SAP Hana Extended Application Services | 31/7/2014 | 17/6/2026 | SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network. | |
| Modificada | Media (6.8) | 3.7% | — | Extended Module Player Project Extended Module Player | 11/2/2014 | 16/6/2026 | Buffer overflow in the get_dsmp function in loaders/masi_load.c in libxmp before 4.1.0 allows remote attackers to execute arbitrary code via a crafted MASI file. | |
| Modificada | Media (4.9) | 0.32% | — | IBM Websphere Transformation Extender | 6/2/2014 | 16/6/2026 | Buffer overflow in the Launcher in IBM WebSphere Transformation Extender 8.4.x before 8.4.0.4 allows local users to cause a denial of service (process crash or Admin Console command-stream outage) via unspecified vectors. | |
| Modificada | Media (4) | 1.9% | — | IBM Websphere Extended Deployment Compute Grid | 28/8/2013 | 16/6/2026 | IBM WebSphere Extended Deployment Compute Grid 8.0 before 8.0.0.3 allows remote authenticated users to obtain sensitive information, and consequently bypass intended access restrictions on jobs, via unspecified vectors. | |
| Modificada | Baja (2.6) | 2.1% | — | Fusedpress Buddypress-extended-frienship-request | 29/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the BuddyPress Extended Friendship Request plugin before 1.0.2 for WordPress, when the "Friend Connections" component is enabled, allows remote attackers to inject arbitrary web script or HTML via the friendship_request_message parameter to wp-admin/admin-ajax.php. NOTE:… | |
| Modificada | Baja (2.6) | 0.78% | — | Verizon Wireless Network Extender | 18/7/2013 | 16/6/2026 | The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to obtain ESN and MIN values from arbitrary phones, and conduct cloning attacks, by sniffing the network for registration packets. | |
| Modificada | Media (6.2) | 0.72% | — | Verizon Wireless Network Extender | 18/7/2013 | 16/6/2026 | The Verizon Wireless Network Extender SCS-2U01 has a hardcoded password for the root account, which makes it easier for physically proximate attackers to obtain administrative access by leveraging a login prompt. | |
| Modificada | Media (6.2) | 0.73% | — | Verizon Wireless Network Extender | 18/7/2013 | 16/6/2026 | The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot process and obtain a login prompt by connecting a crafted HDMI cable and sending a SysReq interrupt. | |
| Modificada | Media (6.2) | 0.68% | — | Verizon Wireless Network Extender | 18/7/2013 | 16/6/2026 | The Uboot bootloader on the Verizon Wireless Network Extender SCS-26UC4 allows physically proximate attackers to obtain root access by connecting a crafted HDMI cable and using a sys session to modify the ramboot environment variable. | |
| Modificada | Alta (7.5) | 5.4% | — | EMC Applicationxtender DesktopEMC Applicationxtender WEB Access .net | 26/8/2012 | 16/6/2026 | EMC ApplicationXtender Desktop before 6.5 SP2 and ApplicationXtender Web Access .NET before 6.5 SP2 allow remote attackers to upload files to any location, and possibly execute arbitrary code, via unspecified vectors. |