Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 1.3% | — | Oracle Customer Relationship Management Technical Foundation | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle CRM Technical… | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Customer Relationship Management Technical Foundation | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle CRM Technical… | |
| Modificada | Alta (8.2) | 1.1% | — | Oracle Customer Relationship Management Technical Foundation | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle CRM Technical… | |
| Modificada | Media (5.9) | 1.4% | — | Oracle Micros Relate Customer Relationship Management Software | 16/10/2019 | 17/6/2026 | Vulnerability in the MICROS Relate CRM Software product of Oracle Retail Applications (component: Internal Operations). Supported versions that are affected are 7.1.0, 15.0.0, 16.0.0, 17.0.0, and 18.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Modificada | Media (5.4) | 0.53% | — | SAP Customer Relationship Management BbpcrmSAP Customer Relationship Management S4crm | 8/10/2019 | 17/6/2026 | SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client resulting in Cross-Site Scripting vulnerability. | |
| Modificada | Alta (8.2) | 1.1% | — | Oracle Micros Relate Customer Relationship Management Software | 23/4/2019 | 17/6/2026 | Vulnerability in the MICROS Relate CRM Software component of Oracle Retail Applications (subcomponent: Customer). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise MICROS Relate CRM Software. While the… | |
| Modificada | Media (5.4) | 0.76% | — | SAP Customer Relationship Management Webclient UISAP S4fndSapscore | 8/1/2019 | 17/6/2026 | SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (5.4) | 0.76% | — | SAP Customer Relationship Management Webclient UISAP S4fndSapscore | 8/1/2019 | 17/6/2026 | SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (6.4) | 1.1% | — | Oracle Micros Relate Customer Relationship Management Software | 18/7/2018 | 17/6/2026 | Vulnerability in the MICROS Relate CRM Software component of Oracle Retail Applications (subcomponent: Internal Operations). Supported versions that are affected are 10.8.x and 11.4.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MICROS Relate CRM Software.… | |
| Modificada | Alta (8.2) | 2.0% | — | Oracle Customer Relationship Management Technical Foundation | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Alta (8.2) | 2.0% | — | Oracle Customer Relationship Management Technical Foundation | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Media (6.6) | 29% | ⚠ Explotación activa💥 Exploit | SAP Customer Relationship Management | 1/3/2018 | 17/6/2026 | SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs. | |
| Modificada | Media (6.1) | 0.96% | — | SAP Customer Relationship Management Webclient UISAP S4fnd | 14/2/2018 | 17/6/2026 | SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (8.1) | 1.3% | — | Oracle Siebel Customer Relationship Management Desktop | 18/1/2018 | 17/6/2026 | Vulnerability in the Siebel CRM Desktop component of Oracle Siebel CRM (subcomponent: Outlook Client). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Desktop. Successful attacks of this… | |
| Modificada | Media (4.3) | 1.3% | — | Oracle Customer Relationship Management Technical Foundation | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Modificada | Media (5.3) | 1.4% | — | Oracle Siebel Customer Relationship Management Desktop | 19/10/2017 | 17/6/2026 | Vulnerability in the Siebel CRM Desktop component of Oracle Siebel CRM (subcomponent: Siebel Business Service Issues). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Desktop. Successful… | |
| Modificada | Alta (8.8) | 0.55% | — | SAP Customer Relationship Management | 16/10/2017 | 17/6/2026 | The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964. | |
| Modificada | Media (6.1) | 0.98% | — | SAP Customer Relationship Management | 16/10/2017 | 17/6/2026 | The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964. | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Customer Relationship Management Technical Foundation | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: User Management). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Customer Relationship Management Technical Foundation | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: CMRO). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Customer Relationship Management Technical Foundation | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Customer Relationship Management Technical Foundation | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: User Interface). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Customer Relationship Management Technical Foundation | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: User Interface). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.… | |
| Modificada | Alta (8.2) | 1.6% | — | Oracle Customer Relationship Management Technical Foundation | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: User Interface). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.… | |
| Modificada | Media (4.3) | 1.5% | — | Oracle Customer Relationship Management Technical Foundation | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote authenticated users to affect confidentiality via unknown vectors. |