Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2747▼ 495 respecto a la semana anterior
Críticas / altas1308▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

3817 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.4)0.95%—SAP Application Server FOR AbapAISAP Netweaver RfcsdkAI13/1/202617/6/2026
Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary…
AnalizadaAlta (8.1)0.26%—SAP Netweaver Application Server Abap13/1/202617/6/2026
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system…
ModificadaCrítica (9.6)1.3%💥 PoCRedhat Build OF Apache CamelRedhat Data GridRedhat FuseRedhat Jboss Enterprise Application Platform+47/1/20266/10/2026
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling…
AplazadaAlta (8.1)0.38%—Mars Multi-application Recovery ServiceAI2/1/202617/6/2026
An SQL injection vulnerability has been reported to affect MARS (Multi-Application Recovery Service). The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: MARS (Multi-Application Recovery Service) 1.2.1.1686…
AplazadaCrítica (9.3)1.0%—Telenium Online WEB ApplicationAI24/12/20257/10/2026
Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an attacker can inject arbitrary Perl code through a crafted HTTP request, leading to remote code execution on the server.
AnalizadaMedia (6.1)1.1%—Zohocorp Manageengine Applications Manager18/12/202530/9/2026
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
AplazadaMedia (6.5)0.33%—SAP Application Server AbapAI9/12/20257/10/2026
Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation could lead to unauthorized disclosure of data, resulting in a high impact on confidentiality without affecting integrity or availability.
AnalizadaMedia (5.4)0.17%—IBM Websphere Application Server8/12/20257/10/2026
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious…
AplazadaMedia (5.4)0.23%—Application PasswordsAI6/12/202517/6/2026
The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' parameter in all versions up to, and including, 0.1.3. This is due to insufficient input sanitization and output escaping on user supplied URLs, which allows javascript: URI schemes to be embedded in the…
ModificadaCrítica (9.8)0.62%—Microsoft Azure Application Gateway26/11/202517/6/2026
Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.62%—Microsoft Azure Application Gateway26/11/202517/6/2026
Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)0.34%—Desktopalert Pingalert Application Server24/11/202517/6/2026
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Incorrect Access Control, leading to Remote Information Disclosure.
AnalizadaCrítica (9.9)0.72%—Desktopalert Pingalert Application Server24/11/202517/6/2026
A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to write arbitrary files under certain conditions.
AnalizadaMedia (5.3)0.22%—Desktopalert Pingalert Application Server24/11/202517/6/2026
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuration values.
AnalizadaAlta (7.5)0.28%—Desktopalert Pingalert Application Server24/11/202517/6/2026
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to disclose user hashes.
AplazadaBaja (2.7)0.38%—Atisoluciones Ciges ApplicationAI24/11/202517/6/2026
A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Application version 2.15.6 and earlier. When certain unexpected conditions trigger unhandled exceptions, the application returns detailed error messages and stack traces to the client. This may expose…
AplazadaAlta (7.7)0.14%—Mitsubishielectric Milco.s Setting ApplicationAIMitsubishielectric Milco.s Easy Setting ApplicationAIMitsubishielectric Milco.s Easy Switch ApplicationAI18/11/202517/6/2026
Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S Setting Application all versions, MILCO.S Setting Application (IR) all versions, MILCO.S Easy Setting Application (IR) all versions, and MILCO.S Easy Switch Application (IR) all versions allows a…
AplazadaAlta (7.2)0.16%—IBM Application ServerAI14/11/20257/10/2026
The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical escalation of privileges. The vulnerability can…
AnalizadaMedia (4.3)0.22%—Desktopalert Pingalert Application Server14/11/202517/6/2026
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Technical Information to be Disclosed through stack trace.
AnalizadaMedia (4.3)0.20%—Desktopalert Pingalert Application Server14/11/202517/6/2026
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote access to content despite lack of the correct permission through a Broken Authorization Schema.
AnalizadaBaja (3.8)0.19%—Desktopalert Pingalert Application Server14/11/202517/6/2026
A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Probing of internal infrastructure.
AnalizadaBaja (3.7)0.28%—Desktopalert Pingalert Application Server14/11/202517/6/2026
An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote Path Traversal for loading arbitrary external content.
AnalizadaMedia (6.5)0.17%—Desktopalert Pingalert Application Server14/11/202517/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.
AnalizadaAlta (7.6)0.25%—Desktopalert Pingalert Application Server14/11/202517/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.
AnalizadaAlta (7.5)0.30%—Desktopalert Pingalert Application Server14/11/202517/6/2026
An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Information is exposed to an Unauthorized Actor.