Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

657 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.1%—Contelligent C1 Financial Services3/3/200716/6/2026
MoveSortedContentAction en C1 Financial Services Contelligent 9.1.4 no valida "el entorno de configuración de seguridad adicional," lo cual permite a atacantes remotos con permisos de escritura reordenar componentes.
ModificadaAlta (10)1.7%—Sybase Financial Fusion Consumer Banking Solution18/7/200616/6/2026
Vulnerabilidad no especificada en Sybase/Financial Fusion Consumer Banking Suite versiones anteriores a 20060706 tiene un impacto desconocido y vectores de ataque remotos.
ModificadaMedia (4.9)0.45%—Jiwa Financials1/6/200616/6/2026
JIWA Financials 6.4.14 stores usernames and passwords for all accounts in cleartext in the HR_Staff table in Microsoft SQL Server, and sends the usernames and passwords in cleartext to the application's SQL Server ODBC driver, which might allow context-dependent attackers to obtain the passwords.
ModificadaMedia (6.5)1.5%—Jiwa Financials1/6/200616/6/2026
JIWA Financials 6.4.14 passes a Microsoft SQL Server account's username and password, and the name of a data source, to a Crystal Reports .rpt file, which allows remote authenticated users to execute certain standard stored procedures by referencing them in a user-written .rpt file, as demonstrated by using a stored…
ModificadaBaja (3.3)0.27%—Lawson Software Lawson Financials31/12/200216/6/2026
Lawson Financials 8.0, when configured to use a third party relational database, stores usernames and passwords in a world-readable file, which allows local users to read the passwords and log onto the database.
ModificadaMedia (5)1.3%—Navision Financials Server18/6/200116/6/2026
Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.
ModificadaMedia (5)1.3%—Navision Financials Server18/6/200116/6/2026
Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.
Orbitaley — Vulnerabilidades