Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
657 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.20% | — | Entrust Instant Financial IssuanceAI | 23/9/2024 | 17/6/2026 | Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. WebAPI.cfg.xml) after the installation process. This file can be accessed without authentication on HTTP port 80 by guessing the correct… | |
| Modificada | Media (6.1) | 0.26% | — | Oracle Financial Services Revenue Management AND Billing | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Chatbot). Supported versions that are affected are 6.0.0.0.0 and 6.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Analizada | Alta (8.1) | 0.40% | — | Oracle Process Manufacturing Financials | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Allocation Rules). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process… | |
| Aplazada | Media (5) | 0.30% | — | SAP Financial ConsolidationAI | 11/6/2024 | 17/6/2026 | SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. These endpoints are exposed over the network. The vulnerability can exploit resources beyond the vulnerable component. On successful exploitation, an attacker can cause limited impact… | |
| Aplazada | Alta (8.1) | 0.37% | — | SAP Financial ConsolidationAI | 11/6/2024 | 17/6/2026 | SAP Financial Consolidation allows data to enter a Web application through an untrusted source. These endpoints are exposed over the network and it allows the user to modify the content from the web site. On successful exploitation, an attacker can cause significant impact to confidentiality and integrity of the… | |
| Modificada | Alta (8.1) | 0.72% | — | Unit4 Financials BY Coda | 20/3/2024 | 9/7/2026 | Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request. | |
| Aplazada | Media (6.1) | 1.8% | 💥 Exploit | Unit4 Financials BY CodaAI | 19/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted GET request using the cols parameter. | |
| Modificada | Alta (7.4) | 0.32% | — | Oracle Financial Services Analytical Applications Infrastructure | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8, 8.0.9, 8.1.0, 8.1.1 and 8.1.2. Easily exploitable vulnerability allows low privileged attacker with… | |
| Modificada | Alta (7.5) | 0.54% | — | IBM Financial Transaction Manager | 25/12/2023 | 17/6/2026 | In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM X-Force ID: 273183. | |
| Modificada | Media (5.3) | 1.1% | — | Systematica Financial CalculatorSystematica FIX AdapterSystematica Http AdapterSystematica Mssql Messagebus Proxy+2 | 30/11/2023 | 17/6/2026 | Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote attackers to read arbitrary files via a full pathname in GET parameter "file" in URL. Also: affected components in same product - HTTP Adapter (up to v.1.8.0.15),… | |
| Modificada | Crítica (9.1) | 1.1% | — | IBM Financial Transaction Manager | 5/9/2023 | 17/6/2026 | IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 258786. | |
| Modificada | Media (5.4) | 0.37% | — | IBM Financial Transaction Manager FOR Multiplatform | 29/4/2023 | 17/6/2026 | IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 239707. | |
| Modificada | Media (4.3) | 0.49% | — | Oracle Financial Services Behavior Detection Platform | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Application). The supported version that is affected is 8.0.8.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Baja (3.3) | 0.19% | — | IBM Financial Transaction Manager | 15/3/2023 | 17/6/2026 | IBM Financial Transaction Manager for High Value Payments for Multi-Platform 3.2.0 through 3.2.10 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 183329. | |
| Modificada | Alta (8.8) | 0.58% | — | IBM Financial Transaction Manager | 10/3/2023 | 17/6/2026 | IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. IBM X-Force ID: 192954. | |
| Modificada | Alta (7.5) | 0.75% | — | IBM Financial Transaction Manager | 1/3/2023 | 17/6/2026 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 193662. | |
| Modificada | Alta (7.5) | 1.0% | — | IBM Financial Transaction Manager | 1/3/2023 | 17/6/2026 | IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 192953. | |
| Modificada | Media (5.5) | 0.19% | — | IBM Financial Transaction Manager | 20/12/2022 | 17/6/2026 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock additional RM authorizations, resulting in a denial of service on displaying or managing these authorizations. IBM X-Force ID: 240034. | |
| Modificada | Media (5.3) | 0.50% | — | IBM Financial Transaction Manager | 20/12/2022 | 17/6/2026 | IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708. | |
| Modificada | Media (6.1) | 0.44% | — | SAP Financial Consolidation | 8/11/2022 | 17/6/2026 | SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject a web script via a GET request. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the… | |
| Modificada | Media (6.5) | 0.40% | — | SAP Financial Consolidation | 8/11/2022 | 17/6/2026 | Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when running a common query in the Web Administration Console. On successful exploitation, an attacker can view or modify information causing a limited impact on… | |
| Modificada | Media (5.4) | 0.44% | — | SAP Financial Consolidation | 8/11/2022 | 17/6/2026 | Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or modify information, causing a limited impact on confidentiality and integrity of the application. | |
| Modificada | Media (5.9) | 0.52% | — | Oracle Financial Services Revenue Management AND Billing | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 2.9.0.0.0, 2.9.0.1.0, 3.0.0.0.0-3.2.0.0.0 and 4.0.0.0.0. Difficult to exploit vulnerability allows low privileged… | |
| Modificada | Crítica (9.8) | 1.1% | — | IBM Financial Transaction Manager | 15/6/2022 | 17/6/2026 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 166801. | |
| Modificada | Media (6.5) | 0.66% | — | SAP ERP Financial AccountingSAP ERP Localization FOR CEE CountriesSAP S/4hana | 14/6/2022 | 17/6/2026 | Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted. |