Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

3817 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.6)0.98%—SAP Netweaver Application Server Abap14/3/202317/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files. In this attack, no data can…
ModificadaMedia (5.3)0.45%—SAP Netweaver Application Server FOR Java14/3/202317/6/2026
SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and…
ModificadaMedia (5.3)0.48%—SAP Netweaver Application Server FOR Java14/3/202317/6/2026
Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity
ModificadaAlta (7.4)0.37%—SAP Netweaver Application Server Abap14/3/202317/6/2026
Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which…
ModificadaMedia (6.5)0.61%—SAP Netweaver Application Server Abap14/3/202317/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an attacker authenticated as a non-administrative user can craft a request with certain parameters…
ModificadaMedia (5.3)0.58%—SAP Netweaver Application Server Java14/3/202317/6/2026
SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an unassigned user can read non-sensitive…
ModificadaAlta (8.6)0.54%—SAP Netweaver Application Server FOR Java14/3/202317/6/2026
Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and services across systems. On a…
ModificadaMedia (6.5)0.75%—Gitlab Dynamic Application Security Testing Analyzer9/3/202317/6/2026
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
ModificadaMedia (6.1)0.54%—Gitlab Dynamic Application Security Testing Analyzer9/3/202317/6/2026
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.
ModificadaMedia (6.5)0.80%—Gitlab Dynamic Application Security Testing Analyzer8/3/202317/6/2026
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.
ModificadaMedia (5.4)0.49%—IBM Maximo Application SuiteIBM Maximo Asset Management2/3/202317/6/2026
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within…
ModificadaMedia (5.5)0.19%—IBM Maximo Application Suite24/2/202317/6/2026
IBM Maximo Application Suite 8.8.0 y 8.9.0 almacena información potencialmente confidencial que podría ser leída por un usuario local. ID de IBM X-Force: 241584.
ModificadaAlta (8.8)0.36%—Cisco Application Policy Infrastructure ControllerCisco Cloud Network Controller23/2/202317/6/2026
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This…
ModificadaAlta (7.5)0.60%—Redhat Build OF QuarkusRedhat Integration Camel FOR Spring BootRedhat Integration Camel KRedhat Integration Service Registry+623/2/202317/6/2026
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
ModificadaAlta (7.5)0.50%—IBM Maximo Application SuiteIBM Maximo Asset Management17/2/202317/6/2026
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 237587.
ModificadaAlta (7.5)0.75%—Solarwinds Server AND Application Monitor15/2/202317/6/2026
Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos.
ModificadaAlta (7.8)0.22%—Suse Linux Enterprise Module FOR SAP ApplicationsOpensuse LeapSuse Linux Enterprise Server15/2/202317/6/2026
Una vulnerabilidad de permisos predeterminados incorrectos en la fórmula saphanabootstrap del módulo SUSE Linux Enterprise para aplicaciones SAP 15-SP1, SUSE Linux Enterprise Server para SAP 12-SP5; openSUSE Leap 15.4 permite a atacantes locales escalar a root manipulando la configuración sudo que se crea. Este…
ModificadaMedia (6.1)0.39%—SAP Netweaver Application Server Abap14/2/202317/6/2026
SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticated attacker to inject the code that can be executed by the application over the network. On successful exploitation it can gain access to the sensitive information which…
ModificadaMedia (6.1)0.39%—SAP Netweaver Application Server Abap14/2/202317/6/2026
Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on…
ModificadaMedia (6.1)0.36%—SAP Netweaver Application Server Abap14/2/202317/6/2026
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose…
ModificadaMedia (6.1)0.40%—SAP Netweaver Application Server Abap14/2/202317/6/2026
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information.
ModificadaMedia (6.1)0.37%—SAP Netweaver Application Server Abap14/2/202317/6/2026
Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and might be directed with the response to…
ModificadaMedia (5.4)0.46%—SAP Netweaver Application Server Abap14/2/202317/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
ModificadaMedia (6.1)0.35%—SAP Netweaver Application Server Abap14/2/202317/6/2026
An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some…
ModificadaMedia (6.1)0.59%—Exoplatform Chat Application6/2/202317/6/2026
A vulnerability classified as problematic has been found in eXo Chat Application. Affected is an unknown function of the file application/src/main/webapp/vue-app/components/ExoChatMessageComposer.vue of the component Mention Handler. The manipulation leads to cross site scripting. It is possible to launch the attack…
Orbitaley — Vulnerabilidades