Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 2.1% | — | SAP DmisSAP S4coreSapscore | 15/9/2021 | 17/6/2026 | DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute manipulated query in NDZT tool to gain access to… | |
| Modificada | Alta (7.2) | 4.1% | 💥 PoC | Underscorejs UnderscoreDebian LinuxTenable.scFedoraproject Fedora | 29/3/2021 | 17/6/2026 | The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized. | |
| Modificada | Media (5.4) | 2.8% | 💥 Exploit | Scoreme Project Scoreme | 17/9/2019 | 17/6/2026 | The ScoreMe theme through 2016-04-01 for WordPress has XSS via the s parameter. | |
| Modificada | Media (5.4) | 0.76% | — | SAP Customer Relationship Management Webclient UISAP S4fndSapscore | 8/1/2019 | 17/6/2026 | SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (5.4) | 0.76% | — | SAP Customer Relationship Management Webclient UISAP S4fndSapscore | 8/1/2019 | 17/6/2026 | SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (8.8) | 1.4% | — | SapscoreSAP S4coreSAP Ea-finservSAP Bank/cfm | 8/1/2019 | 17/6/2026 | SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0; Bank/CFM 4.63_20) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |
| Modificada | Media (5.4) | 0.97% | — | Marketing SapscoreSAP Marketing Uicuan | 11/12/2018 | 17/6/2026 | SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (4.6) | 0.83% | — | SapscoreSAP S4coreSAP Ea-finserv | 9/5/2018 | 17/6/2026 | SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |
| Modificada | Media (5) | 1.8% | — | Oracle Balanced Scorecard | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Balanced Scorecard component in Oracle E-Business Suite 11.5.10.2 and 12.1 allows remote attackers to affect confidentiality via unknown vectors. | |
| Modificada | Crítica (10) | 3.5% | — | Colorscore Project Colorscore | 8/1/2016 | 17/6/2026 | The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary code via shell metacharacters in the (1) image_path, (2) colors, or (3) depth variable. | |
| Modificada | Media (4.3) | 1.6% | — | Walk Score Project Walk Score | 2/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in frame-maker.php in the Walk Score plugin 0.5.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) o parameter. | |
| Modificada | Alta (9) | 12% | — | HP Executive Scorecard | 19/6/2014 | 17/6/2026 | Directory traversal vulnerability in the fndwar web application in HP Executive Scorecard 9.40 and 9.41 allows remote authenticated users to execute arbitrary code, or obtain sensitive information or delete data, via unspecified vectors, aka ZDI-CAN-2120. | |
| Modificada | Alta (7.1) | 5.3% | — | HP Executive Scorecard | 19/6/2014 | 17/6/2026 | Directory traversal vulnerability in the Content Acceleration Pack (CAP) web application in HP Executive Scorecard 9.40 and 9.41 allows remote authenticated users to execute arbitrary code by uploading an executable file, aka ZDI-CAN-2117. | |
| Modificada | Alta (10) | 13% | — | HP Executive Scorecard | 19/6/2014 | 17/6/2026 | The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116. | |
| Modificada | Baja (2.6) | 4.1% | 💥 Exploit | Ezjscore | 17/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 3.6% | — | ZTE Score M | 29/5/2012 | 16/6/2026 | The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application. | |
| Modificada | Media (6.8) | 9.5% | 💥 Exploit | Lispeltuut COM Archeryscores | 4/5/2010 | 16/6/2026 | Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Chipmunk Scripts Cmscore | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | Artscore Studios Cutecast Forum | 31/12/2002 | 16/6/2026 | ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file. |