Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
657 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.1% | — | Contelligent C1 Financial Services | 3/3/2007 | 16/6/2026 | MoveSortedContentAction en C1 Financial Services Contelligent 9.1.4 no valida "el entorno de configuración de seguridad adicional," lo cual permite a atacantes remotos con permisos de escritura reordenar componentes. | |
| Modificada | Alta (10) | 1.7% | — | Sybase Financial Fusion Consumer Banking Solution | 18/7/2006 | 16/6/2026 | Vulnerabilidad no especificada en Sybase/Financial Fusion Consumer Banking Suite versiones anteriores a 20060706 tiene un impacto desconocido y vectores de ataque remotos. | |
| Modificada | Media (4.9) | 0.45% | — | Jiwa Financials | 1/6/2006 | 16/6/2026 | JIWA Financials 6.4.14 stores usernames and passwords for all accounts in cleartext in the HR_Staff table in Microsoft SQL Server, and sends the usernames and passwords in cleartext to the application's SQL Server ODBC driver, which might allow context-dependent attackers to obtain the passwords. | |
| Modificada | Media (6.5) | 1.5% | — | Jiwa Financials | 1/6/2006 | 16/6/2026 | JIWA Financials 6.4.14 passes a Microsoft SQL Server account's username and password, and the name of a data source, to a Crystal Reports .rpt file, which allows remote authenticated users to execute certain standard stored procedures by referencing them in a user-written .rpt file, as demonstrated by using a stored… | |
| Modificada | Baja (3.3) | 0.27% | — | Lawson Software Lawson Financials | 31/12/2002 | 16/6/2026 | Lawson Financials 8.0, when configured to use a third party relational database, stores usernames and passwords in a world-readable file, which allows local users to read the passwords and log onto the database. | |
| Modificada | Media (5) | 1.3% | — | Navision Financials Server | 18/6/2001 | 16/6/2026 | Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits. | |
| Modificada | Media (5) | 1.3% | — | Navision Financials Server | 18/6/2001 | 16/6/2026 | Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash. |