Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2671▼ 680 respecto a la semana anterior
Críticas / altas1271▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)230▼ 272 respecto a la semana anterior
2286 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.24% | — | Creativemindssolutions CM Business DirectoryAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Business Directory cm-business-directory allows Stored XSS.This issue affects CM Business Directory: from n/a through <= 1.5.3. | |
| Aplazada | Media (5.4) | 0.29% | — | BBR Plugins Better Business ReviewsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Business Reviews: from n/a through <= 0.1.1. | |
| Aplazada | Media (5.3) | 0.34% | — | Businessdirectoryplugin Business Directory PluginAI | 18/2/2026 | 17/6/2026 | The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check in all versions up to, and including, 6.4.20. This makes it possible for unauthenticated attackers to modify arbitrary listings, including changing titles, content, and email addresses, by directly… | |
| Aplazada | Alta (7.5) | 0.54% | 💥 PoC | Businessdirectoryplugin Business Directory PluginAI | 18/2/2026 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'payment' parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Alta (8.6) | 0.25% | — | Plunet BusinessmanagerAI | 11/2/2026 | 17/6/2026 | A vulnerability in Plunet Plunet BusinessManager allows unauthorized actions being performed on behalf of privileged users.This issue affects Plunet BusinessManager: 10.15.1 | |
| Aplazada | Alta (8.7) | 0.36% | — | Plunet BusinessmanagerAI | 11/2/2026 | 17/6/2026 | A vulnerability in Plunet Plunet BusinessManager allows session hijacking, data theft, unauthorized actions on behalf of the user.This issue affects Plunet BusinessManager: 10.15.1. | |
| Analizada | Media (6.1) | 0.18% | — | SAP Business Server Pages | 10/2/2026 | 17/6/2026 | SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and… | |
| Analizada | Media (4.8) | 0.20% | — | SAP Businessobjects Enterprise | 10/2/2026 | 17/6/2026 | SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets executed when the user visits the compromised page.This vulnerability has… | |
| Analizada | Media (6.5) | 0.36% | — | SAP Businessobjects Business Intelligence Platform | 10/2/2026 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable and resulting in the denial of service of… | |
| Analizada | Media (5.8) | 0.10% | — | SAP Business ONE | 10/2/2026 | 17/6/2026 | In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue results in a high impact on… | |
| Analizada | Alta (8.1) | 0.30% | — | SAP Businessobjects Business Intelligence Platform | 10/2/2026 | 17/6/2026 | The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim may click on this malicious URL, resulting in an unvalidated redirect to the attacker-controlled domain and subsequently… | |
| Analizada | Alta (7.5) | 0.38% | — | SAP Businessobjects Business Intelligence Platform | 10/2/2026 | 17/6/2026 | SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authentication, which prevents the legitimate users from accessing the platform. As a result, it has a high impact on the availability but no impact on the confidentiality and… | |
| Analizada | Alta (7.5) | 0.42% | — | SAP Businessobjects Business Intelligence Platform | 10/2/2026 | 17/6/2026 | SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repeatedly submitting these requests, the attacker could induce a persistent service disruption, rendering the CMS completely… | |
| Aplazada | Media (5.1) | 0.20% | — | Business Live Chat SoftwareAI | 7/2/2026 | 17/6/2026 | Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user account roles without authentication. Attackers can craft a malicious HTML form to modify user privileges by submitting a POST request to the user creation endpoint with administrative access… | |
| Analizada | Alta (8.1) | 0.25% | — | IBM Cloud PAK FOR Business Automation | 3/2/2026 | 17/6/2026 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existing data due to the improper validation of input length. | |
| Analizada | Media (5.4) | 0.24% | — | IBM Cloud PAK FOR Business Automation | 2/2/2026 | 17/6/2026 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the… | |
| Analizada | Alta (7.1) | 0.52% | — | IBM Business Automation Workflow | 2/2/2026 | 17/6/2026 | IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automation Workflow traditional V25.0.0, V24.0.1, V24.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit… | |
| Aplazada | Alta (8.5) | 0.12% | — | Asus Business ManagerAI | 2/2/2026 | 17/6/2026 | An improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerability can be triggered by a local user sending a specially crafted request, potentially leading to the creation of arbitrary files in a specified path. Refer to the "Security Update for ASUS Business… | |
| Analizada | Alta (7.1) | 0.15% | — | Oracle Business Intelligence | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Oracle Analytics Cloud). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business… | |
| Analizada | Media (5.5) | 0.10% | — | IBM Business Automation Workflow | 20/1/2026 | 17/6/2026 | IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation could allow a local user with access to the container to execute OS system calls. | |
| Analizada | Media (5.5) | 0.13% | — | IBM Business Automation Workflow | 20/1/2026 | 17/6/2026 | IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow containers may disclose sensitve configuration information in a config map. | |
| Analizada | Alta (8.2) | 0.34% | — | Mitel CXMitel Micontact Center Business | 15/1/2026 | 17/6/2026 | A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email… | |
| Analizada | Media (6.1) | 0.20% | — | SAP Business Connector | 13/1/2026 | 17/6/2026 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsuspecting user clicks this link, the user may be redirected to a site controlled by the attacker. Successful exploitation could allow the attacker to access or modify… | |
| Aplazada | Media (4.3) | 0.22% | — | SAP Product Designer WEB UIAISAP Business Server PagesAI | 13/1/2026 | 17/6/2026 | SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application. | |
| Aplazada | Media (6.4) | 0.22% | — | Debt.com Business IN A BOXAI | 9/1/2026 | 17/6/2026 | The Debt.com Business in a Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configuration' parameter of the lead_form shortcode in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… |