Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2286 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.37% | — | Synology Active Backup FOR Business | 27/5/2026 | 7/10/2026 | A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. | |
| Aplazada | Media (5.5) | 0.41% | — | Shenzhen Sixun Software Sixun Shanghui Group Business Management SystemAI | 26/5/2026 | 23/7/2026 | A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the file /api/Dinner/PayConfig. Performing a manipulation of the argument tableno results in sql injection. The attack is possible to be carried out… | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Dynamics 365 Business Central | 12/5/2026 | 10/8/2026 | Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. | |
| Pendiente de análisis | Media (5.4) | 0.12% | — | SAP Businessobjects Business Intelligence PlatformAI | 12/5/2026 | 17/6/2026 | Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the application. There is no impact on confidentiality of the data. | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Business Process Management Suite | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | SAP Business AnalyticsAISAP Content ManagementAI | 14/4/2026 | 17/6/2026 | Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could make unauthorized calls to certain remote function modules, potentially accessing sensitive information beyond their intended permissions. This vulnerability affects confidentiality, with no impact on… | |
| Pendiente de análisis | Media (4.1) | 0.28% | — | SAP Businessobjects Business IntelligenceAI | 14/4/2026 | 17/6/2026 | SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the user�s browser, potentially exposing restricted information. This results in a low impact on confidentiality… | |
| Pendiente de análisis | Crítica (9.9) | 0.55% | — | SAP Business Planning AND ConsolidationAISAP Business WarehouseAI | 14/4/2026 | 17/6/2026 | Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system. | |
| Pendiente de análisis | Media (4.2) | 0.17% | — | SAP Business Objects Business Intelligence PlatformAI | 14/4/2026 | 17/6/2026 | Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victim�s session. If the application continues to accept previously issued tokens after… | |
| Analizada | Crítica (9.1) | 0.33% | — | Mock Business\ | 31/3/2026 | 17/6/2026 | Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::OnlinePayment::StoredTransaction generates a secret key by using a MD5 hash of a single call to the built-in rand function, which is unsuitable for cryptographic use. This key is intended for encrypting… | |
| Pendiente de análisis | Alta (8.7) | 0.38% | — | Tibco Activematrix BusinessworksAITibco Enterprise AdministratorAI | 24/3/2026 | 17/6/2026 | Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour. | |
| Aplazada | Alta (7.1) | 0.29% | — | Meeplace Business Review ScriptAI | 24/3/2026 | 17/6/2026 | Meeplace Business Review Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to the addclick.php endpoint with crafted SQL payloads in the 'id' parameter to extract… | |
| Pendiente de análisis | Media (5.3) | 0.50% | — | Apache ArtemisAIKnime Business HUBAI | 24/3/2026 | 17/6/2026 | Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exchanged via the broker and injection of new message ( CVE-2026-27446 https://www.cve.org/CVERecord ). Since KNIME Business Hub uses Apache Artemis it is also affected by the issue. However, since… | |
| Aplazada | Media (5.3) | 0.29% | — | Rarathemes Business ONE PageAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Business One Page business-one-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business One Page: from n/a through <= 1.3.2. | |
| Aplazada | Media (5.3) | 0.29% | — | Rarathemes Rara BusinessAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Rara Business rara-business allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rara Business: from n/a through <= 1.3.0. | |
| Aplazada | Alta (8.8) | 0.30% | — | Netartmedia PHP Business DirectoryAI | 12/3/2026 | 17/6/2026 | Netartmedia PHP Business Directory 4.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to the loginaction.php endpoint with crafted SQL payloads in the Email field to extract… | |
| Pendiente de análisis | Media (6.9) | 0.11% | — | Asus Business System Control Interface DriverAI | 12/3/2026 | 17/6/2026 | An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Asus Business System Control Interface DriverAI | 12/3/2026 | 17/6/2026 | An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and kernel information… | |
| Pendiente de análisis | Media (5.9) | 0.30% | — | SAP Business WarehouseAI | 10/3/2026 | 17/6/2026 | Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing… | |
| Pendiente de análisis | Media (6.1) | 0.22% | — | SAP Business ONE JOB ServiceAI | 10/3/2026 | 17/6/2026 | Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon user interaction could result in a DOM-based Cross-Site Scripting (XSS) vulnerability. This issue had a low impact on… | |
| Aplazada | Media (6.4) | 0.27% | — | Automotive CAR Dealership BusinessAI | 27/2/2026 | 17/6/2026 | The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Call to Action' custom fields in all versions up to, and including, 13.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the 'action_text',… | |
| Modificada | Crítica (9.8) | 0.69% | — | Edubusinesssolutions Print Shop PRO Webdesk | 20/2/2026 | 17/6/2026 | An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate privileges via the AccessID parameter. | |
| Aplazada | Alta (8.1) | 0.53% | — | Axiomthemes PJ Life AND Business CoachingAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes PJ | Life & Business Coaching pj allows PHP Local File Inclusion.This issue affects PJ | Life & Business Coaching: from n/a through <= 3.0.0. | |
| Aplazada | Alta (7.1) | 0.18% | — | Themebon Business Template Blocks FOR Wpbakery Page BuilderAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Business Template Blocks for WPBakery (Visual Composer) Page Builder templates-and-addons-for-wpbakery-page-builder allows Reflected XSS.This issue affects Business Template Blocks for WPBakery (Visual… | |
| Aplazada | Media (4.3) | 0.25% | — | Ikreatethemes Business ROYAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in ikreatethemes Business Roy business-roy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Roy: from n/a through <= 1.1.4. |