Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 513 respecto a la semana anterior
Críticas / altas1299▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3817 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.20% | — | SAP Netweaver Application Server Abap | 10/3/2026 | 17/6/2026 | Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has low impact on the application's confidentiality with no effect on… | |
| Analizada | Media (6.4) | 0.21% | — | SAP Netweaver Application Server Abap | 10/3/2026 | 17/6/2026 | Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This unauthorized content change could lead to reduced system performance or… | |
| Modificada | Alta (8.1) | 0.49% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/3/2026 | 14/9/2026 | A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative… | |
| Modificada | Alta (8.6) | 0.38% | 💥 PoC | Xwiki Blog Application | 4/3/2026 | 5/8/2026 | The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability arises because the post title is injected directly into the HTML <title> tag… | |
| Analizada | Crítica (9.8) | 0.18% | — | IBM Websphere Application Server | 3/3/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings. | |
| Aplazada | Media (5.5) | 0.09% | — | Cisco Application Policy Infrastructure ControllerAI | 25/2/2026 | 17/6/2026 | A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have valid… | |
| Analizada | Media (4.9) | 0.33% | — | IBM Websphere Application Server | 17/2/2026 | 17/6/2026 | IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings. | |
| Aplazada | Media (4.3) | 0.24% | — | TR7 Cyber Defense INC WEB Application FirewallAI | 16/2/2026 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in TR7 Cyber Defense Inc. Web Application Firewall allows Phishing. This issue affects Web Application Firewall: from 4.30 before v1.4.0.117. | |
| Modificada | Alta (7.1) | 0.48% | — | Kostasmitroglou Password Management Application | 12/2/2026 | 17/6/2026 | thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL code like ' or '1=1 to the username field to gain unauthorized access to user accounts. | |
| Modificada | Alta (7.1) | 0.48% | — | Kostasmitroglou Password Management Application | 12/2/2026 | 17/6/2026 | TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Attackers can inject malicious SQL code like ' or '1=1 to retrieve unauthorized database records and potentially access sensitive system information. | |
| Analizada | Baja (3.4) | 0.17% | — | SAP Netweaver Application Server Java | 10/2/2026 | 17/6/2026 | Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing… | |
| Analizada | Crítica (9.9) | 0.52% | — | SAP Netweaver Application Server AbapSAP S/4hanaSAP Webclient UI Framework | 10/2/2026 | 17/6/2026 | An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on… | |
| Analizada | Media (5.5) | 0.44% | — | Fabian Online Application System FOR Admission | 8/2/2026 | 17/6/2026 | A vulnerability was determined in code-projects Online Application System for Admission 1.0. Affected by this vulnerability is an unknown functionality of the file enrollment/index.php of the component Login Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Alta (8.5) | 0.15% | — | Wondershare Application Framework ServiceAI | 6/2/2026 | 17/6/2026 | Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific directory locations to hijack the… | |
| Analizada | Alta (8.2) | 0.21% | — | F5 Big-ip Advanced WEB Application FirewallF5 Big-ip Application Security Manager | 4/2/2026 | 17/6/2026 | When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Baja (2.3) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 4/2/2026 | 17/6/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (7.6) | 0.48% | — | IBM Websphere Application Server | 2/2/2026 | 17/6/2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution. | |
| Aplazada | Alta (8.5) | 0.17% | — | Iskysoft Application Framework ServiceAI | 1/2/2026 | 17/6/2026 | Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that would be run with the… | |
| Aplazada | Crítica (9.5) | 1.5% | — | Johnsoncontrols Metasys Application AND Data ServerAIJohnsoncontrols Metasys Extended Application AND Data ServerAIJohnsoncontrols Lcs8500AIJohnsoncontrols Nae8500AI+2 | 30/1/2026 | 17/6/2026 | Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects | |
| Aplazada | Alta (8.5) | 0.19% | — | Atheros Coex Service ApplicationAI | 27/1/2026 | 17/6/2026 | Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup. | |
| Analizada | Media (6.5) | 0.37% | — | Oracle Applications DBA | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of… | |
| Analizada | Media (5.4) | 0.19% | — | IBM Application Gateway | 20/1/2026 | 17/6/2026 | IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Application Gateway | 20/1/2026 | 17/6/2026 | IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (6.8) | 27% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Hypervisor+1 | 13/1/2026 | 10/8/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |
| Aplazada | Baja (3) | 0.14% | — | SAP Netweaver Application Server JavaAI | 13/1/2026 | 17/6/2026 | The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial… |