Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
3817 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.6) | 0.98% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files. In this attack, no data can… | |
| Modificada | Media (5.3) | 0.45% | — | SAP Netweaver Application Server FOR Java | 14/3/2023 | 17/6/2026 | SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and… | |
| Modificada | Media (5.3) | 0.48% | — | SAP Netweaver Application Server FOR Java | 14/3/2023 | 17/6/2026 | Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity | |
| Modificada | Alta (7.4) | 0.37% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which… | |
| Modificada | Media (6.5) | 0.61% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an attacker authenticated as a non-administrative user can craft a request with certain parameters… | |
| Modificada | Media (5.3) | 0.58% | — | SAP Netweaver Application Server Java | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an unassigned user can read non-sensitive… | |
| Modificada | Alta (8.6) | 0.54% | — | SAP Netweaver Application Server FOR Java | 14/3/2023 | 17/6/2026 | Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and services across systems. On a… | |
| Modificada | Media (6.5) | 0.75% | — | Gitlab Dynamic Application Security Testing Analyzer | 9/3/2023 | 17/6/2026 | Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host. | |
| Modificada | Media (6.1) | 0.54% | — | Gitlab Dynamic Application Security Testing Analyzer | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects. | |
| Modificada | Media (6.5) | 0.80% | — | Gitlab Dynamic Application Security Testing Analyzer | 8/3/2023 | 17/6/2026 | An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page. | |
| Modificada | Media (5.4) | 0.49% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 2/3/2023 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within… | |
| Modificada | Media (5.5) | 0.19% | — | IBM Maximo Application Suite | 24/2/2023 | 17/6/2026 | IBM Maximo Application Suite 8.8.0 y 8.9.0 almacena información potencialmente confidencial que podría ser leída por un usuario local. ID de IBM X-Force: 241584. | |
| Modificada | Alta (8.8) | 0.36% | — | Cisco Application Policy Infrastructure ControllerCisco Cloud Network Controller | 23/2/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This… | |
| Modificada | Alta (7.5) | 0.60% | — | Redhat Build OF QuarkusRedhat Integration Camel FOR Spring BootRedhat Integration Camel KRedhat Integration Service Registry+6 | 23/2/2023 | 17/6/2026 | The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol. | |
| Modificada | Alta (7.5) | 0.50% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 17/2/2023 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 237587. | |
| Modificada | Alta (7.5) | 0.75% | — | Solarwinds Server AND Application Monitor | 15/2/2023 | 17/6/2026 | Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos. | |
| Modificada | Alta (7.8) | 0.22% | — | Suse Linux Enterprise Module FOR SAP ApplicationsOpensuse LeapSuse Linux Enterprise Server | 15/2/2023 | 17/6/2026 | Una vulnerabilidad de permisos predeterminados incorrectos en la fórmula saphanabootstrap del módulo SUSE Linux Enterprise para aplicaciones SAP 15-SP1, SUSE Linux Enterprise Server para SAP 12-SP5; openSUSE Leap 15.4 permite a atacantes locales escalar a root manipulando la configuración sudo que se crea. Este… | |
| Modificada | Media (6.1) | 0.39% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticated attacker to inject the code that can be executed by the application over the network. On successful exploitation it can gain access to the sensitive information which… | |
| Modificada | Media (6.1) | 0.39% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on… | |
| Modificada | Media (6.1) | 0.36% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose… | |
| Modificada | Media (6.1) | 0.40% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information. | |
| Modificada | Media (6.1) | 0.37% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and might be directed with the response to… | |
| Modificada | Media (5.4) | 0.46% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |
| Modificada | Media (6.1) | 0.35% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some… | |
| Modificada | Media (6.1) | 0.59% | — | Exoplatform Chat Application | 6/2/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in eXo Chat Application. Affected is an unknown function of the file application/src/main/webapp/vue-app/components/ExoChatMessageComposer.vue of the component Mention Handler. The manipulation leads to cross site scripting. It is possible to launch the attack… |