Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3) | 0.14% | — | SAP Netweaver Application Server JavaAI | 13/1/2026 | 17/6/2026 | The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial… | |
| Aplazada | Alta (8.4) | 0.95% | — | SAP Application Server FOR AbapAISAP Netweaver RfcsdkAI | 13/1/2026 | 17/6/2026 | Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary… | |
| Analizada | Alta (8.1) | 0.26% | — | SAP Netweaver Application Server Abap | 13/1/2026 | 17/6/2026 | Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system… | |
| Modificada | Crítica (9.6) | 1.3% | 💥 PoC | Redhat Build OF Apache CamelRedhat Data GridRedhat FuseRedhat Jboss Enterprise Application Platform+4 | 7/1/2026 | 6/10/2026 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling… | |
| Aplazada | Alta (8.1) | 0.38% | — | Mars Multi-application Recovery ServiceAI | 2/1/2026 | 17/6/2026 | An SQL injection vulnerability has been reported to affect MARS (Multi-Application Recovery Service). The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: MARS (Multi-Application Recovery Service) 1.2.1.1686… | |
| Aplazada | Crítica (9.3) | 1.0% | — | Telenium Online WEB ApplicationAI | 24/12/2025 | 7/10/2026 | Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an attacker can inject arbitrary Perl code through a crafted HTTP request, leading to remote code execution on the server. | |
| Analizada | Media (6.1) | 1.1% | — | Zohocorp Manageengine Applications Manager | 18/12/2025 | 30/9/2026 | Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view. | |
| Aplazada | Media (6.5) | 0.33% | — | SAP Application Server AbapAI | 9/12/2025 | 7/10/2026 | Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation could lead to unauthorized disclosure of data, resulting in a high impact on confidentiality without affecting integrity or availability. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Websphere Application Server | 8/12/2025 | 7/10/2026 | IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious… | |
| Aplazada | Media (5.4) | 0.23% | — | Application PasswordsAI | 6/12/2025 | 17/6/2026 | The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' parameter in all versions up to, and including, 0.1.3. This is due to insufficient input sanitization and output escaping on user supplied URLs, which allows javascript: URI schemes to be embedded in the… | |
| Modificada | Crítica (9.8) | 0.62% | — | Microsoft Azure Application Gateway | 26/11/2025 | 17/6/2026 | Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.62% | — | Microsoft Azure Application Gateway | 26/11/2025 | 17/6/2026 | Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.34% | — | Desktopalert Pingalert Application Server | 24/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Incorrect Access Control, leading to Remote Information Disclosure. | |
| Analizada | Crítica (9.9) | 0.72% | — | Desktopalert Pingalert Application Server | 24/11/2025 | 17/6/2026 | A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to write arbitrary files under certain conditions. | |
| Analizada | Media (5.3) | 0.22% | — | Desktopalert Pingalert Application Server | 24/11/2025 | 17/6/2026 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuration values. | |
| Analizada | Alta (7.5) | 0.28% | — | Desktopalert Pingalert Application Server | 24/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to disclose user hashes. | |
| Aplazada | Baja (2.7) | 0.38% | — | Atisoluciones Ciges ApplicationAI | 24/11/2025 | 17/6/2026 | A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Application version 2.15.6 and earlier. When certain unexpected conditions trigger unhandled exceptions, the application returns detailed error messages and stack traces to the client. This may expose… | |
| Aplazada | Alta (7.7) | 0.14% | — | Mitsubishielectric Milco.s Setting ApplicationAIMitsubishielectric Milco.s Easy Setting ApplicationAIMitsubishielectric Milco.s Easy Switch ApplicationAI | 18/11/2025 | 17/6/2026 | Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S Setting Application all versions, MILCO.S Setting Application (IR) all versions, MILCO.S Easy Setting Application (IR) all versions, and MILCO.S Easy Switch Application (IR) all versions allows a… | |
| Aplazada | Alta (7.2) | 0.16% | — | IBM Application ServerAI | 14/11/2025 | 7/10/2026 | The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical escalation of privileges. The vulnerability can… | |
| Analizada | Media (4.3) | 0.22% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Technical Information to be Disclosed through stack trace. | |
| Analizada | Media (4.3) | 0.20% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote access to content despite lack of the correct permission through a Broken Authorization Schema. | |
| Analizada | Baja (3.8) | 0.19% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Probing of internal infrastructure. | |
| Analizada | Baja (3.7) | 0.28% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote Path Traversal for loading arbitrary external content. | |
| Analizada | Media (6.5) | 0.17% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information. | |
| Analizada | Alta (7.6) | 0.25% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information. |