Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
–

3843 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.45%—SAP NetweaverSAP Netweaver Application Server Abap11/4/202317/6/2026
SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a malicious URL and lure the victim to…
ModificadaMedia (6.1)99%—Zohocorp Manageengine Applications Manager11/4/202317/6/2026
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.
ModificadaMedia (6.5)3.2%—Zohocorp Manageengine Applications Manager11/4/202317/6/2026
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
ModificadaMedia (6.1)0.36%—Survey Application System Project Survey Application System7/4/202317/6/2026
A vulnerability was found in SourceCodester Survey Application System 1.0 and classified as problematic. This issue affects some unknown processing of the component Add New Handler. The manipulation of the argument Title with the input <script>prompt(document.domain)</script> leads to cross site scripting. The attack…
ModificadaAlta (7.1)1.1%—IBM Tririga Application Platform7/4/202317/6/2026
IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249975.
ModificadaMedia (5.4)0.37%—IBM Tririga Application Platform7/4/202317/6/2026
IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 241036.
ModificadaMedia (5.4)0.37%—IBM Websphere Application Server2/4/202317/6/2026
IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248416.
ModificadaMedia (6.1)0.36%—Oretnom23 Earnings AND Expense Tracker Application29/3/202317/6/2026
A vulnerability classified as problematic has been found in SourceCodester Earnings and Expense Tracker App 1.0. This affects an unknown part of the file Master.php?a=save_expense. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated…
ModificadaMedia (4.3)0.80%—Gitlab Dynamic Application Security Testing Analyzer27/3/202317/6/2026
An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where Authorization headers was leaked in vulnerability report evidence.
ModificadaCrítica (9.1)21%—Generalbytes Crypto Application Server22/3/202317/6/2026
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in…
ModificadaMedia (6.5)0.33%—IBM Manage Application15/3/202317/6/2026
IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to a user to actions that they should not have access to. IBM X-Force ID: 242953.
ModificadaCrítica (9.6)0.97%—SAP Netweaver Application Server Abap14/3/202317/6/2026
SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to exploit insufficient validation of path information provided by users, thus exploiting a directory traversal flaw in an available service to delete system files. In this…
ModificadaAlta (8.1)0.98%—SAP Netweaver Application Server Abap14/3/202317/6/2026
An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable.
ModificadaMedia (6.5)0.61%—SAP Netweaver Application Server Abap14/3/202317/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in a class for test purposes in which an attacker authenticated as a non-administrative user can craft a request with certain parameters, which will…
ModificadaCrítica (9.6)0.98%—SAP Netweaver Application Server Abap14/3/202317/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files. In this attack, no data can…
ModificadaMedia (5.3)0.45%—SAP Netweaver Application Server FOR Java14/3/202317/6/2026
SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and…
ModificadaMedia (5.3)0.48%—SAP Netweaver Application Server FOR Java14/3/202317/6/2026
Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity
ModificadaAlta (7.4)0.37%—SAP Netweaver Application Server Abap14/3/202317/6/2026
Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which…
ModificadaMedia (6.5)0.61%—SAP Netweaver Application Server Abap14/3/202317/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an attacker authenticated as a non-administrative user can craft a request with certain parameters…
ModificadaMedia (5.3)0.58%—SAP Netweaver Application Server Java14/3/202317/6/2026
SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an unassigned user can read non-sensitive…
ModificadaAlta (8.6)0.54%—SAP Netweaver Application Server FOR Java14/3/202317/6/2026
Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and services across systems. On a…
ModificadaMedia (6.5)0.75%—Gitlab Dynamic Application Security Testing Analyzer9/3/202317/6/2026
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
ModificadaMedia (6.1)0.54%—Gitlab Dynamic Application Security Testing Analyzer9/3/202317/6/2026
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.
ModificadaMedia (6.5)0.80%—Gitlab Dynamic Application Security Testing Analyzer8/3/202317/6/2026
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.
ModificadaMedia (5.4)0.49%—IBM Maximo Application SuiteIBM Maximo Asset Management2/3/202317/6/2026
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within…