Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2814▼ 267 respecto a la semana anterior
Críticas / altas1316▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
2277 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 98% | ⚠ Explotación activa💥 Exploit | Hitachi Vantara Pentaho Business Analytics Server | 3/4/2023 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream. | |
| Modificada | Media (6.5) | 0.30% | — | Cisco Business 150ax FirmwareCisco Business 151axm FirmwareCisco Catalyst 9105ax FirmwareCisco Catalyst 9105axi Firmware+27 | 23/3/2023 | 17/6/2026 | A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 frames. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (8.8) | 0.85% | — | Eclipse Business Intelligence AND Reporting Tools | 15/3/2023 | 17/6/2026 | In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTTP path for the report parameter (e.g. __report=http://xyz.com/report.rptdesign). If the host indicated in the __report parameter matched the HTTP Host header value, the report… | |
| Modificada | Alta (7.5) | 0.52% | — | SAP Businessobjects Business Intelligence | 14/3/2023 | 17/6/2026 | In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability. | |
| Modificada | Media (5.3) | 0.62% | — | SAP Businessobjects Business Intelligence | 14/3/2023 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine… | |
| Modificada | Alta (7.5) | 0.57% | — | SAP Businessobjects Business Intelligence Platform | 14/3/2023 | 17/6/2026 | In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own admintools, leading to a high impact on availability. | |
| Modificada | Alta (8.8) | 0.93% | — | SAP Business Objects Business Intelligence Platform | 14/3/2023 | 17/6/2026 | SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom application based on the public java SDK.… | |
| Modificada | Alta (8.8) | 0.95% | — | SAP Business Objects Business Intelligence Platform | 14/3/2023 | 17/6/2026 | In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. Successful attack could highly impact the confidentiality,… | |
| Modificada | Media (5.4) | 0.39% | — | IBM Cloud PAK FOR Business Automation | 27/2/2023 | 17/6/2026 | IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended… | |
| Modificada | Media (5.4) | 0.48% | — | Business Management System Project Business Management System | 24/2/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1. | |
| Modificada | Media (5.4) | 0.39% | — | Tibco Businessconnect | 22/2/2023 | 17/6/2026 | The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are… | |
| Modificada | Media (5.4) | 0.40% | — | Tibco Businessconnect | 22/2/2023 | 17/6/2026 | The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO… | |
| Modificada | Crítica (9.1) | 0.56% | — | SAP Businessobjects Business Intelligence Platform | 14/2/2023 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform operations that may completely compromise the application causing high… | |
| Modificada | Media (6.1) | 0.36% | — | SAP Netweaver AS Abap Business Server Pages | 14/2/2023 | 17/6/2026 | Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a Reflected Cross-Site Scripting (XSS) attack. As a result, an… | |
| Modificada | Media (6.1) | 0.39% | — | SAP Netweaver AS Abap Business Server Pages | 14/2/2023 | 17/6/2026 | Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This… | |
| Modificada | Media (5.4) | 0.34% | — | SAP Business Objects Business Intelligence Platform | 14/2/2023 | 17/6/2026 | In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful… | |
| Modificada | Media (5.4) | 0.34% | — | SAP Business Planning AND Consolidation | 14/2/2023 | 17/6/2026 | SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their… | |
| Modificada | Alta (7.1) | 0.52% | — | SAP Businessobjects Business Intelligence Platform | 14/2/2023 | 17/6/2026 | SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality and limited impact on integrity of the application. | |
| Modificada | Alta (7.5) | 0.60% | — | Mitel Micontact Center Business | 13/2/2023 | 17/6/2026 | El componente ccmweb del servidor Mitel MiContact Center Business 9.2.2.0 a 9.4.1.0 podría permitir a un atacante no autenticado descargar archivos arbitrarios, debido a una restricción insuficiente de los parámetros de URL. Un exploit exitoso podría permitir el acceso a información confidencial. | |
| Modificada | Media (5.3) | 0.44% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated attacker could potentially exploit this vulnerability and impersonate a legitimate dell customer to a dell support technician. | |
| Modificada | Alta (7.1) | 0.16% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive information in the database of the affected… | |
| Modificada | Alta (7.8) | 0.15% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system. | |
| Modificada | Media (5.5) | 0.17% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. | |
| Modificada | Media (5.5) | 0.13% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. | |
| Modificada | Alta (7.8) | 0.23% | — | Dell Alienware UpdateDell Command UpdateDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS+1 | 11/2/2023 | 17/6/2026 | Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may… |