Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 1.8% | — | Oracle Customer Relationship Management Technical Foundation | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Media (4.3) | 1.5% | — | Oracle Customer Relationship Management Technical Foundation | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle CRM Technology Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0579, CVE-2016-0582, and CVE-2016-0583. | |
| Modificada | Media (4.3) | 1.5% | — | Oracle Customer Relationship Management Technical Foundation | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle CRM Technology Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0579, CVE-2016-0583, and CVE-2016-0584. | |
| Modificada | Media (4.3) | 1.5% | — | Oracle Customer Relationship Management Technical Foundation | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle CRM Technology Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0582, CVE-2016-0583, and CVE-2016-0584. | |
| Modificada | Media (6.4) | 1.7% | — | Oracle Customer Relationship Management Technical Foundation | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle CRM Technology Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to BIS Common Components. | |
| Modificada | Media (6.4) | 1.7% | — | Oracle Customer Relationship Management Technical Foundation | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to CRM HTML Administration. | |
| Modificada | Alta (7.5) | 1.4% | — | SAP Customer Relationship Management | 12/5/2015 | 17/6/2026 | SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534. | |
| Modificada | Alta (7.5) | 2.4% | — | SAP Customer Relationship Management | 12/5/2015 | 17/6/2026 | Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534. | |
| Modificada | Alta (10) | 5.5% | — | SAP Customer Relationship Management | 6/11/2014 | 17/6/2026 | The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 2.8% | — | SAP Customer Relationship Management Internet Sales | 6/11/2014 | 17/6/2026 | The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors. | |
| Modificada | Media (5) | 1.5% | — | SAP Customer Relationship Management | 14/2/2014 | 17/6/2026 | Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue. | |
| Modificada | Alta (10) | 2.1% | — | SAP Customer Relationship Management | 13/12/2013 | 17/6/2026 | The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue. | |
| Modificada | Media (5.5) | 0.87% | — | Oracle Peoplesoft Enterprise Customer Relationship Management | 20/4/2011 | 16/6/2026 | Unspecified vulnerability in Oracle PeopleSoft Enterprise CRM 8.9 Bundle #41 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Order Capture. | |
| Modificada | Media (5.5) | 2.5% | — | Oracle ApexOracle Application ServerOracle Collaboration SuiteOracle Database Server+5 | 18/7/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims… | |
| Modificada | Alta (10) | 3.8% | — | Oracle Peoplesoft Enterprise Customer Relationship Management | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in Enterprise CRM Sales in Oracle 8.81 up to 8.9 has unknown impact and attack vectors, as identified by Oracle Vuln# CRM01. |