Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)2.1%—SAP DmisSAP S4coreSapscore15/9/202117/6/2026
DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute manipulated query in NDZT tool to gain access to…
ModificadaAlta (7.2)4.1%💥 PoCUnderscorejs UnderscoreDebian LinuxTenable.scFedoraproject Fedora29/3/202117/6/2026
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
ModificadaMedia (5.4)2.8%💥 ExploitScoreme Project Scoreme17/9/201917/6/2026
The ScoreMe theme through 2016-04-01 for WordPress has XSS via the s parameter.
ModificadaMedia (5.4)0.76%—SAP Customer Relationship Management Webclient UISAP S4fndSapscore8/1/201917/6/2026
SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
ModificadaMedia (5.4)0.76%—SAP Customer Relationship Management Webclient UISAP S4fndSapscore8/1/201917/6/2026
SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
ModificadaAlta (8.8)1.4%—SapscoreSAP S4coreSAP Ea-finservSAP Bank/cfm8/1/201917/6/2026
SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0; Bank/CFM 4.63_20) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
ModificadaMedia (5.4)0.97%—Marketing SapscoreSAP Marketing Uicuan11/12/201817/6/2026
SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
ModificadaMedia (4.6)0.83%—SapscoreSAP S4coreSAP Ea-finserv9/5/201817/6/2026
SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
ModificadaMedia (5)1.8%—Oracle Balanced Scorecard21/1/201617/6/2026
Unspecified vulnerability in the Oracle Balanced Scorecard component in Oracle E-Business Suite 11.5.10.2 and 12.1 allows remote attackers to affect confidentiality via unknown vectors.
ModificadaCrítica (10)3.5%—Colorscore Project Colorscore8/1/201617/6/2026
The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary code via shell metacharacters in the (1) image_path, (2) colors, or (3) depth variable.
ModificadaMedia (4.3)1.6%—Walk Score Project Walk Score2/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in frame-maker.php in the Walk Score plugin 0.5.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) o parameter.
ModificadaAlta (9)12%—HP Executive Scorecard19/6/201417/6/2026
Directory traversal vulnerability in the fndwar web application in HP Executive Scorecard 9.40 and 9.41 allows remote authenticated users to execute arbitrary code, or obtain sensitive information or delete data, via unspecified vectors, aka ZDI-CAN-2120.
ModificadaAlta (7.1)5.3%—HP Executive Scorecard19/6/201417/6/2026
Directory traversal vulnerability in the Content Acceleration Pack (CAP) web application in HP Executive Scorecard 9.40 and 9.41 allows remote authenticated users to execute arbitrary code by uploading an executable file, aka ZDI-CAN-2117.
ModificadaAlta (10)13%—HP Executive Scorecard19/6/201417/6/2026
The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116.
ModificadaBaja (2.6)4.1%💥 ExploitEzjscore17/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (10)3.6%—ZTE Score M29/5/201216/6/2026
The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application.
ModificadaMedia (6.8)9.5%💥 ExploitLispeltuut COM Archeryscores4/5/201016/6/2026
Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)2.3%💥 ExploitChipmunk Scripts Cmscore2/5/200516/6/2026
Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.
ModificadaAlta (7.5)6.7%💥 ExploitArtscore Studios Cutecast Forum31/12/200216/6/2026
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file.
Orbitaley — Vulnerabilidades