Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
3843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.45% | — | SAP NetweaverSAP Netweaver Application Server Abap | 11/4/2023 | 17/6/2026 | SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a malicious URL and lure the victim to… | |
| Modificada | Media (6.1) | 99% | — | Zohocorp Manageengine Applications Manager | 11/4/2023 | 17/6/2026 | Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page. | |
| Modificada | Media (6.5) | 3.2% | — | Zohocorp Manageengine Applications Manager | 11/4/2023 | 17/6/2026 | Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack. | |
| Modificada | Media (6.1) | 0.36% | — | Survey Application System Project Survey Application System | 7/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Survey Application System 1.0 and classified as problematic. This issue affects some unknown processing of the component Add New Handler. The manipulation of the argument Title with the input <script>prompt(document.domain)</script> leads to cross site scripting. The attack… | |
| Modificada | Alta (7.1) | 1.1% | — | IBM Tririga Application Platform | 7/4/2023 | 17/6/2026 | IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249975. | |
| Modificada | Media (5.4) | 0.37% | — | IBM Tririga Application Platform | 7/4/2023 | 17/6/2026 | IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 241036. | |
| Modificada | Media (5.4) | 0.37% | — | IBM Websphere Application Server | 2/4/2023 | 17/6/2026 | IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248416. | |
| Modificada | Media (6.1) | 0.36% | — | Oretnom23 Earnings AND Expense Tracker Application | 29/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Earnings and Expense Tracker App 1.0. This affects an unknown part of the file Master.php?a=save_expense. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated… | |
| Modificada | Media (4.3) | 0.80% | — | Gitlab Dynamic Application Security Testing Analyzer | 27/3/2023 | 17/6/2026 | An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where Authorization headers was leaked in vulnerability report evidence. | |
| Modificada | Crítica (9.1) | 21% | — | Generalbytes Crypto Application Server | 22/3/2023 | 17/6/2026 | General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in… | |
| Modificada | Media (6.5) | 0.33% | — | IBM Manage Application | 15/3/2023 | 17/6/2026 | IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to a user to actions that they should not have access to. IBM X-Force ID: 242953. | |
| Modificada | Crítica (9.6) | 0.97% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to exploit insufficient validation of path information provided by users, thus exploiting a directory traversal flaw in an available service to delete system files. In this… | |
| Modificada | Alta (8.1) | 0.98% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable. | |
| Modificada | Media (6.5) | 0.61% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in a class for test purposes in which an attacker authenticated as a non-administrative user can craft a request with certain parameters, which will… | |
| Modificada | Crítica (9.6) | 0.98% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files. In this attack, no data can… | |
| Modificada | Media (5.3) | 0.45% | — | SAP Netweaver Application Server FOR Java | 14/3/2023 | 17/6/2026 | SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and… | |
| Modificada | Media (5.3) | 0.48% | — | SAP Netweaver Application Server FOR Java | 14/3/2023 | 17/6/2026 | Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity | |
| Modificada | Alta (7.4) | 0.37% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which… | |
| Modificada | Media (6.5) | 0.61% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an attacker authenticated as a non-administrative user can craft a request with certain parameters… | |
| Modificada | Media (5.3) | 0.58% | — | SAP Netweaver Application Server Java | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an unassigned user can read non-sensitive… | |
| Modificada | Alta (8.6) | 0.54% | — | SAP Netweaver Application Server FOR Java | 14/3/2023 | 17/6/2026 | Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and services across systems. On a… | |
| Modificada | Media (6.5) | 0.75% | — | Gitlab Dynamic Application Security Testing Analyzer | 9/3/2023 | 17/6/2026 | Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host. | |
| Modificada | Media (6.1) | 0.54% | — | Gitlab Dynamic Application Security Testing Analyzer | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects. | |
| Modificada | Media (6.5) | 0.80% | — | Gitlab Dynamic Application Security Testing Analyzer | 8/3/2023 | 17/6/2026 | An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page. | |
| Modificada | Media (5.4) | 0.49% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 2/3/2023 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within… |