Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

47 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)1.8%—Microsoft Lync ServerMicrosoft Skype FOR Business Server25/2/202117/6/2026
Skype for Business and Lync Spoofing Vulnerability
ModificadaMedia (6.1)0.90%—SAP Netweaver AS Abap Business Server Pages9/9/202017/6/2026
SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,752,753,754,755, allows an unauthenticated attacker to send polluted URL to the victim, when the victim clicks on this URL, the attacker can read, modify the information available in the victim�s browser leading to…
ModificadaMedia (6.1)0.65%—SAP Netweaver AS Abap Business Server Pages10/6/202017/6/2026
SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
ModificadaMedia (6.1)0.80%—SAP Netweaver AS Abap Business Server Pages24/4/202017/6/2026
SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulnerable to reflected Cross-Site Scripting (XSS) via different URL parameters as it does not sufficiently encode user controlled inputs.
ModificadaMedia (6.1)0.65%—SAP Netweaver AS Abap Business Server Pages14/4/202017/6/2026
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
ModificadaMedia (6.1)1.6%—SAP Netweaver AS Abap Business Server Pages14/4/202017/6/2026
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.
ModificadaMedia (6.1)0.65%—SAP Netweaver AS Abap Business Server Pages14/4/202017/6/2026
SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
ModificadaMedia (6.1)0.77%—SAP Netweaver AS Abap Business Server Pages10/3/202017/6/2026
SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54; does not sufficiently encode user controlled inputs, allowing an unauthenticated attacker to non-permanently deface or modify displayed content and/or steal…
ModificadaMedia (6.1)2.1%—Microsoft Lync ServerMicrosoft Skype FOR Business Server9/4/201917/6/2026
A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'.
ModificadaAlta (8.1)7.2%—HP Converged Infrastructure Solution Sizer SuiteHP Insight Management SizerHP Power AdvisorHP SAP Sizing Tool+1122/8/201617/6/2026
HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2, Insight Management Sizer before 16.12.1, Synergy Planning Tool before 3.3, SAP Sizing Tool before 16.12.1, Sizing Tool for SAP Business Suite powered by HANA before…
ModificadaMedia (4.3)8.9%—Microsoft Lync ServerMicrosoft Skype FOR Business Server9/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS Elevation of Privilege Vulnerability."
ModificadaMedia (4.3)11%—Microsoft Lync ServerMicrosoft Skype FOR Business Server9/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the jQuery engine in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS Information Disclosure Vulnerability."
ModificadaAlta (7.8)34%—ISC BindSuse Linux Enterprise Software Development KITNovell Suse LinuxISC Dnsco Bind+829/7/201316/6/2026
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA…
ModificadaAlta (8.8)8.6%💥 ExploitMcafee E-business Server10/1/200816/6/2026
The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long initial authentication packet.
ModificadaAlta (7.1)32%—Microsoft Home ServerMicrosoft Small Business ServerMicrosoft Windows 2000Microsoft Windows 2003 Server+28/1/200816/6/2026
The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."
ModificadaAlta (9.3)6.2%—Mcafee E-business Server31/10/200716/6/2026
Integer overflow in McAfee E-Business Server before 8.5.3 for Solaris, and before 8.1.2 for Linux, HP-UX, and AIX, allows remote attackers to execute arbitrary code via a large length value in an authentication packet, which results in a heap-based buffer overflow.
ModificadaAlta (7.6)6.3%—Mcafee Common Management AgentMcafee E-business ServerMcafee Protectionpilot12/7/200716/6/2026
Heap-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 through 3.6.0.453 allows remote attackers to execute arbitrary code via a crafted packet.
ModificadaAlta (7.6)4.0%—Mcafee E-business ServerMcafee Protectionpilot12/7/200716/6/2026
Integer underflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and earlier allows remote attackers to execute arbitrary code via a crafted UDP packet, which causes stack corruption.
ModificadaAlta (7.5)3.6%—Mcafee Common Management AgentMcafee E-business ServerMcafee Protectionpilot12/7/200716/6/2026
Stack-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and earlier allows remote attackers to execute arbitrary code via a crafted ping packet.
ModificadaMedia (5)1.9%—Mcafee E-business Server19/4/200716/6/2026
The administration server in McAfee e-Business Server before 8.1.1 and 8.5.x before 8.5.2 allows remote attackers to cause a denial of service (service crash) via a large length value in a malformed authentication packet, which triggers a heap over-read.
ModificadaMedia (5)3.5%💥 ExploitNiti Telecom Caravan Business Server31/12/200416/6/2026
Directory traversal vulnerability in sample_showcode.html in Caravan 2.00/03d and earlier allows remote attackers to read arbitrary files via the fname parameter.
ModificadaAlta (7.5)1.4%—PGP Corporate DesktopPGP E-business ServerPGP FreewarePGP Personal Security+14/9/200116/6/2026
PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by…
Orbitaley — Vulnerabilidades